Get the latest tech news

Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs


Apache, Alibaba databases vulnerable and only one has a patch

None

Get the Android app

Or read this on The Register

Read more on:

Photo of vendor

vendor

Photo of mcp

mcp

Photo of Bug hunter

Bug hunter

Related news:

News photo

Agent-harness-kit scaffolding for multi-agent workflows (MCP, provider-agnostic)

News photo

200,000 MCP servers expose a command execution flaw that Anthropic calls a feature

News photo

Three AI coding agents leaked secrets through a single prompt injection. One vendor's system card predicted it