Skip to content
Review

Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale

Jul 2026 · 1 citation · ⚡ 1 influential · 16 references
Computer Science

TL;DR

It is found that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles without security review.

Abstract

The Model Context Protocol (MCP) has seen rapid adoption since its November 2024 launch, with over 21,000 server instances detectable on the public internet. We present the first dynamic behavioral security assessment of internet-facing MCP servers, combining passive discovery across eleven data sources (crt.sh, HuggingFace, GitHub, npm, Smithery, PyPI, Censys, FOFA, Shodan, glama.ai, and pulsemcp.com) with active dynamic testing using Corvus, a purpose-built framework implementing 34 test modules covering 10 MCP-specific vulnerability classes. Across four measurement runs spanning July 2026, we confirm 640 production MCP servers and dynamically audit 414, uncovering 68 reportable vulnerabilities including SQL injection, SSRF targeting cloud metadata services, prompt template injection, and path traversal via cursor manipulation. We find that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles without security review. We report on our responsible disclosure pipeline and release Corvus as an open-source framework for MCP security evaluation.

View source

Similar papers

Open access Aug 2026

Security challenges in serverless architectures: Vulnerabilities and penetration testing approaches for AWS Lambda and Google Cloud Functions

This study examines the evolving security landscape of serverless computing, specifically focusing on AWS Lambda and Google Cloud Functions. While serverless architectures offer significant scalability and cost advantages, their event-driven nature introduces unique vulnerabilities that traditional infrastructure-based...

Norsyazwani Mohd Puad, Paiwand Hadi Hama Saeed, Braw Araz Mohammed et al. · 0 citations
Preprint Sep 2026

Same Name, Different Server: A Security Census of Silent Drift in the Model Context Protocol Ecosystem

The Model Context Protocol (MCP) has become the common interface through which large language model applications reach external tools, and its public registry now distributes thousands of community-built servers with little of the vetting infrastructure that mature package ecosystems have accumulated. This paper report...

Obada Kraishan · 2 citations
Open access Aug 2026

Cloud in the crosshairs: exposing vulnerabilities in web-based management interfaces of open-source IaaS platforms

This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.

Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al. · 0 citations
Review Open access Aug 2026

Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges

This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics, and reveals a definitive and strategic maturation in adversarial approach.

Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas et al. · 0 citations
#artificial intelligence Preprint Sep 2026

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in w...

Ze-Hua Zhang, Jie Hu, Pratham Hegde et al. · 0 citations
#data science Open access Oct 2026

Zero Trust for SQL Server: A Three-Layer Security Architecture

This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control with Row-Level Security and Just-in-Time privilege elevation, and metadata-driven Attribute-Based Access Cont...

Maynard Capil, D. Dasig · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.