VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers
Fuente:
arXiv
Guardado en:
| Autores principales: | Sun, Pengyu, Jin, Qishu, Huang, Enhao, Kang, Zifeng, Liu, Xin, Shen, Dakun, Li, Song |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
por: Wang, Bin, et al.
Publicado: (2025)
por: Wang, Bin, et al.
Publicado: (2025)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
por: Ahmadi, Arash, et al.
Publicado: (2025)
por: Ahmadi, Arash, et al.
Publicado: (2025)
Auditing MCP Servers for Over-Privileged Tool Capabilities
por: Huang, Charoes, et al.
Publicado: (2026)
por: Huang, Charoes, et al.
Publicado: (2026)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
por: Song, Hao, et al.
Publicado: (2025)
por: Song, Hao, et al.
Publicado: (2025)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
por: Ghebremichael, Jonah, et al.
Publicado: (2026)
por: Ghebremichael, Jonah, et al.
Publicado: (2026)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
por: Huang, Yiheng, et al.
Publicado: (2026)
por: Huang, Yiheng, et al.
Publicado: (2026)
TaintSentinel: Path-Level Randomness Vulnerability Detection for Ethereum Smart Contracts
por: Rezaei, Hadis, et al.
Publicado: (2025)
por: Rezaei, Hadis, et al.
Publicado: (2025)
Securing the Model Context Protocol (MCP): Risks, Controls, and Governance
por: Errico, Herman, et al.
Publicado: (2025)
por: Errico, Herman, et al.
Publicado: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
por: Ni, Ronghao, et al.
Publicado: (2026)
por: Ni, Ronghao, et al.
Publicado: (2026)
MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
por: Radosevich, Brandon, et al.
Publicado: (2025)
por: Radosevich, Brandon, et al.
Publicado: (2025)
"MCP Does Not Stand for Misuse Cryptography Protocol": Uncovering Cryptographic Misuse in Model Context Protocol at Scale
por: Yan, Biwei, et al.
Publicado: (2025)
por: Yan, Biwei, et al.
Publicado: (2025)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
por: Huang, Charoes, et al.
Publicado: (2026)
por: Huang, Charoes, et al.
Publicado: (2026)
Exploiting Cross-Layer Vulnerabilities: Off-Path Attacks on the TCP/IP Protocol Suite
por: Feng, Xuewei, et al.
Publicado: (2024)
por: Feng, Xuewei, et al.
Publicado: (2024)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
por: Hao, Run, et al.
Publicado: (2026)
por: Hao, Run, et al.
Publicado: (2026)
MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
por: Shen, Yi Ting, et al.
Publicado: (2026)
por: Shen, Yi Ting, et al.
Publicado: (2026)
MCPZoo: A Large-Scale Dataset of Runnable Model Context Protocol Servers for AI Agent
por: Wu, Mengying, et al.
Publicado: (2025)
por: Wu, Mengying, et al.
Publicado: (2025)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
por: Hou, Xinyi, et al.
Publicado: (2025)
por: Hou, Xinyi, et al.
Publicado: (2025)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
por: Zhao, Weibo, et al.
Publicado: (2025)
por: Zhao, Weibo, et al.
Publicado: (2025)
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
por: Zhou, Huijun, et al.
Publicado: (2026)
por: Zhou, Huijun, et al.
Publicado: (2026)
SecureMCP: A Policy-Enforced LLM Data Access Framework for AIoT Systems via Model Context Protocol
por: Kim, Wonbae, et al.
Publicado: (2026)
por: Kim, Wonbae, et al.
Publicado: (2026)
Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
por: Fei, Qingyuan, et al.
Publicado: (2025)
por: Fei, Qingyuan, et al.
Publicado: (2025)
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
por: Wang, Zhiqiang, et al.
Publicado: (2025)
por: Wang, Zhiqiang, et al.
Publicado: (2025)
Taint-Based Code Slicing for LLMs-based Malicious NPM Package Detection
por: Nguyen, Dang-Khoa, et al.
Publicado: (2025)
por: Nguyen, Dang-Khoa, et al.
Publicado: (2025)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
por: Zhang, Dongsen, et al.
Publicado: (2025)
por: Zhang, Dongsen, et al.
Publicado: (2025)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
por: Rostamzadeh, Mehrdad, et al.
Publicado: (2026)
por: Rostamzadeh, Mehrdad, et al.
Publicado: (2026)
BrokerChain: A Blockchain Sharding Protocol by Exploiting Broker Accounts
por: Huang, Huawei, et al.
Publicado: (2024)
por: Huang, Huawei, et al.
Publicado: (2024)
ExtendAttack: Attacking Servers of LRMs via Extending Reasoning
por: Zhu, Zhenhao, et al.
Publicado: (2025)
por: Zhu, Zhenhao, et al.
Publicado: (2025)
Can LLM Infer Risk Information From MCP Server System Logs?
por: Fu, Jiayi, et al.
Publicado: (2025)
por: Fu, Jiayi, et al.
Publicado: (2025)
Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis
por: Ji, Yuchen, et al.
Publicado: (2025)
por: Ji, Yuchen, et al.
Publicado: (2025)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
por: Xing, Wenpeng, et al.
Publicado: (2025)
por: Xing, Wenpeng, et al.
Publicado: (2025)
MCP Safety Training: Learning to Refuse Falsely Benign MCP Exploits using Improved Preference Alignment
por: Halloran, John
Publicado: (2025)
por: Halloran, John
Publicado: (2025)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
por: Xiang, Jiahui, et al.
Publicado: (2024)
por: Xiang, Jiahui, et al.
Publicado: (2024)
Harnessing the Power of LLM to Support Binary Taint Analysis
por: Liu, Puzhuo, et al.
Publicado: (2023)
por: Liu, Puzhuo, et al.
Publicado: (2023)
STAFF: Stateful Taint-Assisted Full-system Firmware Fuzzing
por: Izzillo, Alessio, et al.
Publicado: (2025)
por: Izzillo, Alessio, et al.
Publicado: (2025)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
por: Luo, Yu, et al.
Publicado: (2025)
por: Luo, Yu, et al.
Publicado: (2025)
Model Context Contracts - MCP-Enabled Framework to Integrate LLMs With Blockchain Smart Contracts
por: Bandara, Eranga, et al.
Publicado: (2025)
por: Bandara, Eranga, et al.
Publicado: (2025)
QUIC-Exfil: Exploiting QUIC's Server Preferred Address Feature to Perform Data Exfiltration Attacks
por: Grübl, Thomas, et al.
Publicado: (2025)
por: Grübl, Thomas, et al.
Publicado: (2025)
Penetrating the Hostile: Detecting DeFi Protocol Exploits through Cross-Contract Analysis
por: Li, Xiaoqi, et al.
Publicado: (2025)
por: Li, Xiaoqi, et al.
Publicado: (2025)
LLM Agents can Autonomously Exploit One-day Vulnerabilities
por: Fang, Richard, et al.
Publicado: (2024)
por: Fang, Richard, et al.
Publicado: (2024)
Ejemplares similares
-
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
por: Wang, Bin, et al.
Publicado: (2025) -
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
por: Ahmadi, Arash, et al.
Publicado: (2025) -
Auditing MCP Servers for Over-Privileged Tool Capabilities
por: Huang, Charoes, et al.
Publicado: (2026) -
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
por: Song, Hao, et al.
Publicado: (2025) -
Multi-Agent Taint Specification Extraction for Vulnerability Detection
por: Ghebremichael, Jonah, et al.
Publicado: (2026)