Analysis
MCP Security: Risks, Cases and Controls
Publication date unknown · Discovered ebuildersecurity.se
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
MCP has grown past 10,000 public servers connecting AI agents to real tools and data, making its instructions-and-data-in-one-channel design a board-level supply-chain risk that defenders must govern and monitor.
eBuilder Security's MCP Security guide explains the Model Context Protocol's core weakness—placing instructions and data in the same channel so a tool's plain-text description can steer an agent—and synthesizes known cases including tool poisoning (MCPTox benchmark 36.5% average attack success), the malicious postmark-mcp server that BCC'd emails to an attacker, Asana's cross-tenant MCP logic flaw, and two critical RCE CVEs (CVE-2025-6514 in mcp-remote, CVE-2025-49596 in MCP Inspector). The piece recommends treating every MCP server as untrusted third-party code and keeping a human in the loop for consequential actions.