MCP Security Incidents

Security incidents involving Model Context Protocol servers and tooling: supply-chain campaigns, credential disclosure, path traversal, and SSRF. Each entry links to primary sources and the disclosed CVE where one exists.

Showing 1 - 10 of 10

highongoing

Deadbugz malicious MCP server supply-chain campaign

A malicious MCP server distributed via GitHub pull requests behaves benignly for three tool calls, then rewrites its metadata into instructions that hunt SSH keys and cloud credentials once the client trusts it.

mcpsupply-chaincredential-theftgithub
highresolved

Atlassian MCP path traversal (CVE-2026-73498)

The confluence_upload_attachment tool failed to validate file paths, letting any authenticated MCP client read arbitrary files accessible to the server process. CVSS 7.7, fixed in v0.22.0.

mcpatlassianpath-traversalCVE-2026-73498
criticalongoing

Langflow CVE-2026-55255 exploited in the wild

Help Net Security reported active exploitation of a CVSS 9.9 cross-tenant IDOR in Langflow, the AI-orchestration platform that sits behind most MCP deployments.

mcplangflowidorcredential-theftCVE-2026-55255exploited-in-wild
criticalongoing

Sysdig discloses JadePuffer agentic ransomware

Sysdig disclosed JadePuffer, an LLM agent running an entire ransomware operation without a human in the loop: initial access through a Langflow RCE (CVE-2025-3248) and a Nacos auth bypass, then autonomous recon, credential theft, and database extortion.

mcpagentransomwareautonomouscredential-theft
highongoing

Miasma worm plants adversarial MCP configs across GitHub repos

A worm campaign planted adversarial MCP configuration files across 73 GitHub repositories (including Microsoft's azure/durabletask), executing credential-harvesting payloads against developers who opened an affected repo in a vulnerable IDE.

mcpsupply-chainwormcredential-theftgithub