The MCP Security Crisis: What We Found Hunting Vulnerabilities Across the Ecosystem

TL;DR AI
2 min readKey summary
Akav Labs says it found recurring security flaws across Model Context Protocol (MCP) servers used by enterprise AI agents.
The issues include unsafe parameter handling, exposed credentials, weak access controls, and missing safety annotations.
Researchers say they confirmed the findings with live proof-of-concept tests, but are withholding vendor names and CVEs during coordinated disclosure.
The concern is that MCP is becoming a core integration layer, so flaws could let attackers steer agent behavior or access sensitive data and operations.
