Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale
Nicolás Padilla
cs.CR, cs.AI
Submitted: 2026-07-31
Comments: 13 pages, 3 figures
Code: https://github.com/CobaltoSec/corvus
License: http://creativecommons.org/licenses/by/4.0/
The gist: The Model Context Protocol (MCP) has seen rapid adoption since its November 2024 launch, with over 21,000 server instances detectable on the public internet.
Terminology
Abstract
The Model Context Protocol (MCP) has seen rapid adoption since its November 2024 launch, with over 21,000 server instances detectable on the public internet. We present the first dynamic behavioral security assessment of internet-facing MCP servers, combining passive discovery across eleven data sources (crt.sh, HuggingFace, GitHub, npm, Smithery, PyPI, Censys, FOFA, Shodan, glama.ai, and pulsemcp.com) with active dynamic testing using Corvus, a purpose-built framework implementing 34 test modules covering 10 MCP-specific vulnerability classes. Across four measurement runs spanning July 2026, we confirm 640 production MCP servers and dynamically audit 414, uncovering 68 reportable vulnerabilities including SQL injection, SSRF targeting cloud metadata services, prompt template injection, and path traversal via cursor manipulation. We find that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles without security review. We report on our responsible disclosure pipeline and release Corvus as an open-source framework for MCP security evaluation.
Sources
- MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
- Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
- A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
- A First Look at the Security Issues in the Model Context Protocol Ecosystem
- VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers
- Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs