New Prompt Injection Attack Vectors Through MCP Sampling
ID: 1c0bb78c-cc8b-5256-abb4-2e8fbeec2801
STIX ID: report--1c0bb78c-cc8b-5256-abb4-2e8fbeec2801
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-12-05
Date Updated: 2026-04-28
Author: Yongzhe Huang, Akshata Rao, Changjiang Li, Yang Ji and Wenjun Hu
This report analyzes security risks in the Model Context Protocol (MCP) sampling feature, demonstrating three proof-of-concept attacks — resource/token theft via hidden prompt content, persistent prompt injection that hijacks conversation behavior, and covert tool invocation enabling unauthorized file writes — and provides detection and mitigation recommendations to limit prompt injection, enforce access controls, and filter/limit sampling requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
