Research · curated 21 Jul 2026
State of MCP Security 2026 v2
First reported · updated · 2 reports canopii.dev
Coverage timeline
Why it matters
MCP servers are the tool-calling backbone of AI agents, and this study quantifies how widespread code-execution sinks, unpinned supply chains, and silent tool-definition rug pulls are across the ecosystem defenders increasingly rely on.
Canopii's "State of MCP Security 2026" report scanned more than 11,000 published Model Context Protocol servers and found 830 graded D or F, 232 with confirmed dangerous code sinks (eval, shell injection, unsafe deserialization) that can turn prompt injection into host code execution, 184 versions that silently altered tool definitions after publication ("rug pulls"), 1,617 servers shipping dependencies with known vulnerabilities, 260 running install-time scripts, and 7 confirmed typosquats. Popular servers with 1,000+ GitHub stars were over 5x more likely to be high-risk.