Analysis

MCP Security: Risks, Cases and Controls

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026ebuildersecurity.seobserved

Single-source analysis — one report is available.

Why it matters

MCP has grown past 10,000 public servers connecting AI agents to real tools and data, making its instructions-and-data-in-one-channel design a board-level supply-chain risk that defenders must govern and monitor.

eBuilder Security's MCP Security guide explains the Model Context Protocol's core weakness—placing instructions and data in the same channel so a tool's plain-text description can steer an agent—and synthesizes known cases including tool poisoning (MCPTox benchmark 36.5% average attack success), the malicious postmark-mcp server that BCC'd emails to an attacker, Asana's cross-tenant MCP logic flaw, and two critical RCE CVEs (CVE-2025-6514 in mcp-remote, CVE-2025-49596 in MCP Inspector). The piece recommends treating every MCP server as untrusted third-party code and keeping a human in the loop for consequential actions.