Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: mcp (13 articles)Clear

Official MCP Python SDK flaw lets malicious servers steal client OAuth credentials

The maintainers of the official Model Context Protocol Python SDK disclosed a flaw that lets a malicious MCP server trick an application built on the SDK into handing over the OAuth credentials it uses to log in to a real service. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, because the SDK did not always verify where the authorization server was. Cycode, which reported it, exchanged the stolen material for a valid access token carrying the app's permissions, and noted the long-lived client secret keeps working until rotated. Fixes are in versions 1.30.0 and 2.2.0.

Check
Upgrade the MCP Python SDK to 1.30.0 or 2.2.0, then rotate any OAuth client secrets that MCP clients may have sent to untrusted servers.
Affected
Applications built on affected MCP Python SDK versions can be induced by a malicious MCP server to leak their OAuth client secret, authorization code, and PKCE key.
Fix
Update the SDK, rotate exposed client secrets, and connect MCP clients only to servers whose authorization endpoints you trust and validate.

Critical Bifrost AI gateway flaw lets unauthenticated attackers run commands and steal provider keys

JFrog disclosed a critical flaw in Bifrost, an open-source AI gateway routing to over twenty LLM providers, that lets an unauthenticated attacker run arbitrary commands on the gateway with a single HTTP request. Tracked as CVE-2026-90898 and rated 9.8, it affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled, which is the default. An attacker registers a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the command immediately, before any handshake, as the gateway user. Because the gateway stores API keys for every connected provider, command execution also exposes those credentials, and the official Docker image binds its management API to all interfaces.

Check
Upgrade Bifrost to transports 2.1.0, enable management authentication, keep the management listener off untrusted networks, and rotate any provider keys the gateway held.
Affected
Bifrost gateways before 2.1.0 with default disabled management auth let an unauthenticated attacker run commands and read every connected provider API key.
Fix
Update to 2.1.0, set governance.auth_config.is_enabled to true with strong credentials, avoid publishing the management port, and treat exposed instances as compromised.

Malicious repository content can make Amazon's Kiro AI IDE leak local data

Researchers showed that Amazon Kiro, an AI-powered agentic development environment, can be turned against its user through prompt injection. Attacker-controlled content in a repository the developer opens can steer the Kiro agent into transmitting sensitive local information to an external server, abusing a feature called Kiro Powers that bundles model context protocol server configurations, steering files, and hooks. The developer only has to open the workspace and interact with the agent. It is part of a wider run of similar flaws in AI coding tools, where untrusted content or links quietly redirect an agent into exfiltrating data or executing code without any approval prompt. Updating the tool addresses the reported issue.

Check
Update Kiro to the latest version, and treat opening untrusted repositories in any agentic AI development environment as risky, since hidden instructions can drive the agent without an approval prompt.
Affected
Developers using Amazon Kiro or similar agentic AI IDEs who open untrusted repositories; malicious content can prompt-inject the agent to exfiltrate local data or alter its own tool and context configuration files.
Fix
Keep agentic IDEs updated, review model context protocol configs and steering files for tampering, limit what secrets and paths the agent can reach, and avoid opening untrusted projects in autonomous tools.

Ruflo AI agent platform exposed 233 tools through an unauthenticated MCP bridge

Noma Labs found a critical flaw in Ruflo, an open-source platform for orchestrating swarms of AI agents that acts as a harness for coding agents like Claude Code and Codex. Tracked as CVE-2026-59726 and scored 10.0, the flaw is that Ruflo's default Docker deployment exposed its Model Context Protocol bridge to the network with no authentication, offering 233 callable tools. A single unauthenticated request could invoke a shell command tool to run code in the bridge container, read AI provider API keys, steal stored conversations, and poison the platform's persistent agent memory, which can steer future outputs even after the attacker leaves. The flaw is in Ruflo, not in the coding agents.

Check
If you run Ruflo, formerly Claude Flow, update to version 3.16.3 or later, and confirm its MCP bridge is not bound to a network-reachable interface.
Affected
Teams running Ruflo before 3.16.3 with the default Docker deployment (CVE-2026-59726); an unauthenticated network attacker can run commands, steal AI provider keys and conversations, and poison persistent agent memory.
Fix
Update Ruflo, rotate AI provider API keys, rebuild affected containers from clean images, inspect the agent memory store for unfamiliar instructions, and keep MCP bridges bound to loopback and behind authentication.

Hidden pull request comments can hijack AI agents via Microsoft's DevOps MCP server

Offensive security firm Manifold Security detailed a confused deputy flaw in Microsoft's official Azure DevOps MCP server, which lets AI agents read and operate Azure DevOps on a user's behalf across pull requests, pipelines, wikis, and work items, using that user's own permissions. One of the server's tools returns pull request descriptions without the prompt injection guardrail Microsoft had already applied to other tools. Because descriptions accept Markdown, an attacker can bury instructions in an HTML comment: the web interface renders it as nothing, so a reviewer sees an ordinary change, while the REST API returns the text verbatim and hands it straight to the agent.

Check
Check whether AI agents in your environment use the Azure DevOps MCP server, and review what permissions those agents inherit, since content written by others becomes instructions the agent may act on.
Affected
Teams running AI agents against Azure DevOps through Microsoft's MCP server; a pull request description containing a hidden HTML comment can steer the agent, which acts with the requesting user's full permissions.
Fix
Treat repository and ticket content reaching an agent as untrusted input, scope MCP server permissions well below the user's own, require human approval for write actions, and monitor agent tool calls.

Poisoned web page could rewrite AWS Kiro's config file and run code

Researchers at Intezer showed that a poisoned web page could take over AWS Kiro, an AI coding tool, by getting the agent to rewrite the file that governs what it is allowed to run. A prompt injection in fetched content drops custom code into the MCP settings file, which executes the moment the file is saved. The same write to execution path was demonstrated on Kiro's release day in July 2025 by another researcher, who also flagged writing to a Visual Studio Code settings file to allowlist shell commands. AWS added an approval prompt, but only in supervised mode, leaving the default autonomous mode writing the file unprompted.

Check
If you use AWS Kiro or similar agentic coding tools, check which mode they run by default and whether the agent can write its own MCP or editor configuration files without approval.
Affected
Developers running AWS Kiro in its default autonomous mode; content fetched from a web page can inject instructions that rewrite the agent's MCP settings file, and saving that file executes attacker-supplied code.
Fix
Require approval for agent writes to configuration files in every mode, keep those files outside what the agent can modify, and treat fetched web content as untrusted rather than trusting mode settings.

FakeGit floods GitHub with fake AI skills and MCP servers that drop malware

Researchers at Island uncovered FakeGit, a campaign running roughly 7,600 malicious GitHub repositories from about 6,600 lookalike developer profiles, of which more than 800 pose as AI skills or Model Context Protocol servers. The fake projects borrow the names and workflows of familiar tools, covering Gmail and WhatsApp integrations through to Databricks, Jenkins, and Docker tooling, and their convincing README files walk a user or an agent from routine setup into downloading a malicious ZIP. That triggers a loader chain ending in SmartLoader, which establishes persistence and pulls further payloads such as the StealC infostealer.

Check
Treat AI skills and MCP servers on GitHub as untrusted code: verify the publishing account and project history before installing, and be wary of setup steps that download a ZIP release.
Affected
Developers and AI agents installing skills or MCP servers from GitHub; more than 800 fake repositories impersonate familiar tools, and following their setup instructions leads to SmartLoader and the StealC infostealer.
Fix
Install AI skills and MCP servers only from verified publishers, review repository history and profile age, scan packages before use, and restrict what credentials and systems an installed MCP server can reach.

Microsoft warns poisoned MCP tool descriptions can make AI agents leak data

Microsoft is warning that attackers can hijack AI agents through poisoned tool descriptions, the plain-text notes that tell an agent what a tool does. Because agents connect to systems through the Model Context Protocol and read these descriptions to decide how to act, an attacker who updates a trusted third-party tool can bury a hidden instruction in its description, telling the agent to quietly collect and exfiltrate data on its next task. Many setups pick up description changes without re-approval, so the poisoned version goes live silently. Each step the agent takes looks legitimate and runs with the user's own permissions, so no alarm fires.

Check
Inventory the MCP tools and servers your AI agents can use, especially third-party ones, and check whether your setup re-approves or reviews tool descriptions when they change rather than trusting updates automatically.
Affected
Organizations running AI agents connected to third-party MCP tools without re-approval on description changes; a poisoned description can redirect the agent to exfiltrate data using the user's own permissions, invisibly.
Fix
Require review when tool descriptions change, pin and verify tool sources, scope agents with least privilege, log every tool invocation at the infrastructure layer, and gate sensitive actions behind human approval.

Amazon Q Developer flaw let a malicious repo steal a developer's cloud keys

Wiz Research found a high-severity flaw in Amazon Q Developer, Amazon's AI coding assistant, that let a malicious code repository run commands and steal a developer's cloud credentials simply by being opened. The bug (CVE-2026-12957) lay in how Amazon Q handled Model Context Protocol servers: it read an MCP configuration file from the open workspace and automatically launched the servers it defined. Because those servers run as local processes that inherit the developer's full environment, a single config file committed to a repo could reach AWS keys, cloud tokens, API secrets, and SSH agent sockets, turning a git clone into a full compromise. Amazon has patched the issue and published an advisory.

Check
Confirm Amazon Q Developer is updated to the patched version, and review whether developers open untrusted repositories in AI coding assistants that can auto-launch Model Context Protocol servers from in-repo configuration files.
Affected
Developers using vulnerable versions of Amazon Q Developer (CVE-2026-12957) who open untrusted repositories; a malicious MCP configuration file could run commands and steal cloud credentials from the developer's environment.
Fix
Update Amazon Q Developer, treat opening a repository in an AI assistant as running its code, disable automatic MCP server launching where possible, and isolate untrusted repos without real credentials.

Agentjacking hijacks AI coding agents via fake Sentry error reports

Researchers at Tenet Security have disclosed Agentjacking, a new attack that turns AI coding assistants like Claude Code, Cursor, and Codex into tools for running an attacker's code on a developer's machine. The trick abuses Sentry, a widely used error-tracking service: anyone can submit a fake error event using a project's DSN, a public write-only key embedded in website code, and the AI agent, fetching that event through Sentry's MCP integration, cannot tell the malicious instructions from real diagnostics and runs them with the developer's privileges. No phishing, malware, or server breach is needed, and it bypasses traditional controls because every step is technically authorized. Tenet found 2,388 exposed organizations.

Check
Inventory developers using AI coding agents connected to Sentry or other MCP integrations that surface external data, and check whether your Sentry DSNs are exposed in frontend code or repositories.
Affected
Development teams using MCP-connected AI coding agents (Claude Code, Cursor, Codex) alongside Sentry; any project whose public DSN lets attackers inject error events that the agent treats as trusted instructions.
Fix
Run AI coding agents with least privilege in sandboxes, require human approval before they execute commands, treat all MCP tool output as untrusted, and limit which integrations feed agents external data.