OWASP has published a working draft of the MCP Top 10, a security framework covering the most critical vulnerabilities in Model Context Protocol servers, tools, clients, and agentic workflows. With over 10,000 active MCP servers and 97 million monthly SDK downloads, the risks are significant. The 10 vulnerabilities covered include token mismanagement and secret exposure, privilege escalation and scope creep, tool poisoning, supply chain attacks, command injection, intent flow subversion (prompt injection), insufficient authentication, lack of audit and telemetry, shadow MCP servers, and context injection and over-sharing. For each risk, real-world examples are provided alongside concrete mitigations such as short-lived tokens, RBAC, cryptographically signed tool manifests, sandboxed execution, OAuth 2.1/mTLS, immutable logging, and namespace isolation for context buffers.

9m read timeFrom nordicapis.com
Post cover image
Table of contents
1. MCP01:2025 Token Mismanagement and Secret Exposure2. MCP02:2025 Privilege Escalation and Scope Creep3. MCP03:2025 Tool Poisoning4. MCP04:2025 Supply Chain Attacks and Dependency Tampering5. MCP05:2025 Command Injection and Execution6. MCP06:2025 Intent Flow Subversion7. MCP07:2025 Insufficient Authentication and Authorization8. MCP08:2025 Lack of Audit and Telemetry9. MCP09:2025 Shadow MCP Servers10. MCP10:2025 Context Injection and Over-SharingSecuring MCP Environments Against the OWASP Top 10AI Summary
212 Impressions