In 2024, the Model Context Protocol (MCP) was introduced as a universal standard for linking AI models, agents, and integrated development environments with various tools and data. Its adoption was rapid, with thousands of developers and enterprises integrating it into their workflows. However, a recent investigation by OX Security has uncovered significant vulnerabilities in the ecosystem, revealing a lack of security measures surrounding community-published MCP servers.
Earlier this year, OX Security identified critical vulnerabilities in the widely downloaded MCP source code from Anthropic. In their latest analysis, they examined servers published on popular MCP marketplaces, uncovering a concerning absence of security protocols. Unlike Google's Bouncer, which scanned Android apps for malware before user access, MCP marketplaces lack any comparable vetting process. This means that anyone can publish a server without scrutiny.
Even with a review process, the problem persists. At security conferences like RSAC and OWASP, it was highlighted how developers often over-rely on the information in public repositories. MCP servers can run backend code that differs from what is publicly available, creating a significant security blind spot. Enterprises have developed stringent governance measures for cloud adoption, including data residency rules, Zero Trust principles, and supply chain audits. However, MCP connections frequently bypass these protective structures.
OX Security's study evaluated 15,465 MCP servers, ultimately identifying 5,095 unique hostnames. The analysis revealed that server locations could be altered post-launch, posing additional risks. The root issue is not the protocol itself but the misplaced trust in its security. Without vetting, code signing, and origin verification in marketplaces, enterprises must take responsibility for securing their interactions with MCP.
To better understand these vulnerabilities, OX Security has published a comprehensive report detailing their findings and threat scenarios. The report emphasizes the urgent need for enhanced governance in the MCP ecosystem to prevent enterprises from becoming victims of these overlooked risks.

