When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
Fuente:
arXiv
Saved in:
| Main Authors: | Zhao, Weibo, Liu, Jiahao, Ruan, Bonan, Li, Shaofei, Liang, Zhenkai |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
VulZoo: A Comprehensive Vulnerability Intelligence Dataset
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026)
by: Ruan, Bonan, et al.
Published: (2026)
Auditing MCP Servers for Over-Privileged Tool Capabilities
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
by: Song, Hao, et al.
Published: (2025)
by: Song, Hao, et al.
Published: (2025)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
by: Tan, Zhuoran, et al.
Published: (2026)
by: Tan, Zhuoran, et al.
Published: (2026)
A Taxonomy of System-Level Attacks on Deep Learning Models in Autonomous Vehicles
by: Tehrani, Masoud Jamshidiyan, et al.
Published: (2024)
by: Tehrani, Masoud Jamshidiyan, et al.
Published: (2024)
Fuzzing Frameworks for Server-side Web Applications: A Survey
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
DevOps-Gym: Benchmarking AI Agents in Software DevOps Cycle
by: Tang, Yuheng, et al.
Published: (2026)
by: Tang, Yuheng, et al.
Published: (2026)
Demonstration Attack against In-Context Learning for Code Intelligence
by: Ge, Yifei, et al.
Published: (2024)
by: Ge, Yifei, et al.
Published: (2024)
A Taxonomy of Functional Security Features and How They Can Be Located
by: Hermann, Kevin, et al.
Published: (2025)
by: Hermann, Kevin, et al.
Published: (2025)
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
by: Houy, Sabine, et al.
Published: (2025)
by: Houy, Sabine, et al.
Published: (2025)
OpenSCV: An Open Hierarchical Taxonomy for Smart Contract Vulnerabilities
by: Vidal, Fernando Richter, et al.
Published: (2023)
by: Vidal, Fernando Richter, et al.
Published: (2023)
From Transactions to Exploits: Automated PoC Synthesis for Real-World DeFi Attacks
by: Su, Xing, et al.
Published: (2026)
by: Su, Xing, et al.
Published: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Bitcoin Cross-Chain Bridge: A Taxonomy and Its Promise in Artificial Intelligence of Things
by: Tang, Guojun, et al.
Published: (2025)
by: Tang, Guojun, et al.
Published: (2025)
Options, Not Clicks: Lattice Refinement for Consent-Driven MCP Authorization
by: Li, Ying, et al.
Published: (2026)
by: Li, Ying, et al.
Published: (2026)
AFLGopher: Accelerating Directed Fuzzing via Feasibility-Aware Guidance
by: Bai, Weiheng, et al.
Published: (2025)
by: Bai, Weiheng, et al.
Published: (2025)
MASKDROID: Robust Android Malware Detection with Masked Graph Representations
by: Zheng, Jingnan, et al.
Published: (2024)
by: Zheng, Jingnan, et al.
Published: (2024)
Usability as a Weapon: Attacking the Safety of LLM-Based Code Generation via Usability Requirements
by: Li, Yue, et al.
Published: (2026)
by: Li, Yue, et al.
Published: (2026)
When Security Meets Usability: An Empirical Investigation of Post-Quantum Cryptography APIs
by: Toruan, Marthin, et al.
Published: (2026)
by: Toruan, Marthin, et al.
Published: (2026)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
When AI Takes the Wheel: Security Analysis of Framework-Constrained Program Generation
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
FDI: Attack Neural Code Generation Systems through User Feedback Channel
by: Sun, Zhensu, et al.
Published: (2024)
by: Sun, Zhensu, et al.
Published: (2024)
Enhancing Pre-Trained Language Models for Vulnerability Detection via Semantic-Preserving Data Augmentation
by: Qi, Weiliang, et al.
Published: (2024)
by: Qi, Weiliang, et al.
Published: (2024)
CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality Shift
by: Yu, Jiongchi, et al.
Published: (2025)
by: Yu, Jiongchi, et al.
Published: (2025)
When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
by: Ma, Jie, et al.
Published: (2026)
by: Ma, Jie, et al.
Published: (2026)
LSPFuzz: Hunting Bugs in Language Servers
by: Zhu, Hengcheng, et al.
Published: (2025)
by: Zhu, Hengcheng, et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
PROMFUZZ: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
BandFuzz: An ML-powered Collaborative Fuzzing Framework
by: Shi, Wenxuan, et al.
Published: (2025)
by: Shi, Wenxuan, et al.
Published: (2025)
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents?
by: Peng, Yibo, et al.
Published: (2025)
by: Peng, Yibo, et al.
Published: (2025)
An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Automatic Selection of Protections to Mitigate Risks Against Software Applications
by: Canavese, Daniele, et al.
Published: (2025)
by: Canavese, Daniele, et al.
Published: (2025)
Automated Attack Synthesis for Constant Product Market Makers
by: Han, Sujin, et al.
Published: (2024)
by: Han, Sujin, et al.
Published: (2024)
Similar Items
-
VulZoo: A Comprehensive Vulnerability Intelligence Dataset
by: Ruan, Bonan, et al.
Published: (2024) -
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024) -
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025) -
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026) -
Auditing MCP Servers for Over-Privileged Tool Capabilities
by: Huang, Charoes, et al.
Published: (2026)