Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
Blog post from Endor Labs
The Model Context Protocol (MCP) was launched by Anthropic in November 2024 to standardize how AI assistants connect to external tools and data sources, quickly gaining popularity as the "USB-C for AI applications." However, its rapid adoption throughout 2025 and 2026 exposed numerous critical vulnerabilities, as security considerations were overlooked in its trust assumptions, implementation, and third-party servers. Common vulnerabilities such as command injection, path traversal, and missing authentication were prevalent, often exacerbated by newer tactics like prompt injection, which expanded the potential attack surface. Several specific vulnerabilities were identified in various MCP implementations, including the Anthropic mcp-server-git and Framelink Figma MCP server, highlighting the risks of processing potentially attacker-controlled content. These vulnerabilities emphasize the need for robust security measures, such as validating and sanitizing input and treating outputs from LLMs and MCP servers as untrusted. The text suggests that AppSec teams should adapt their threat models to treat LLMs as untrusted intermediaries, emphasizing the importance of applying secure coding practices and monitoring MCP activity to mitigate risks. The MCP's first year underscores the necessity of integrating application security into AI infrastructure, as classical vulnerabilities persist alongside novel attack vectors, posing significant challenges for secure AI deployments.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 42 | 2,803 | 327 | 131 | -43% |
| LLM | 15 | 3,836 | 662 | 193 | +2% |
| AI Coding Assistant | 2 | 710 | 191 | 84 | +14% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.