Research · curated 19 Jul 2026
Confused Deputy Attack Against Model Context Protocol | ACM Transactions on Software Engineering and Methodology
First reported acm.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The confused deputy attack exposes a design-level attack surface in MCP tool selection that lets adversarial servers silently hijack agent tool calls and remains invisible to current MCP security scanners, and reasoning-enabled models are found to be more vulnerable.
An ACM TOSEM paper uncovers the "confused deputy attack" against the Model Context Protocol (MCP), where an adversarial server with subtly manipulated metadata overshadows a benign server and intercepts tool invocations without overt malicious behavior. The authors built Puppet, an automated evaluation framework that rewrites benign tool descriptions to hijack tool selection, achieving hijacking rates up to 90.89% and payload execution up to 86.46% across 14 models, while evading MCP-Scan and McpSafetyScanner which cannot detect metadata-level manipulation.