Skip to content

Security1 publisher3 min readPublished

Ox Security finds nearly 16% of public MCP server hostnames resolve outside the US

Ox Security found nearly 16% of 5,095 hostnames listed in three public MCP registries resolve outside the US, including to Russia and China. MCP has no notion of region, so cloud residency rules end where a company's AI agents connect out.

The Watch · Security desk

Illustration accompanying Ox Security finds nearly 16% of public MCP server hostnames resolve outside the US

What happened

  • More than 2% of the hostnames no longer resolve, and some are unregistered and available to buy, so a buyer could impersonate the server the name once pointed to.
  • Anthropic's reply, as Ox relays it, is that this is documented behavior and that model-level detection of malicious content is a best-effort heuristic, not a security boundary.
  • Backslash Security's June 2025 study of 7,000 MCP servers found hundreds reachable by anyone on the same local network via NeighborJack, and about 70 with severe flaws.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Regulated data can leave a company's jurisdiction through an agent's tool call even when every workload the company hosts stays in-region.
  • capability For the price of a domain registration, an attacker can stand up a server at a lapsed address that public registries still hand to agents.
  • decision Anthropic treats both always-allow and its SDK design as intended behavior, so operators decide which MCP hosts an agent may reach, in client config and egress rules.
  • constraint A hostname allowlist has to track registration status, because an approved name that expires and changes hands stays trusted until someone removes it.

The cheapest attack path in Ox Security's data starts with a domain registration. More than 100 of the 5,095 hostnames no longer resolve [2]. Anyone who buys one of the names still for sale can pose as the server it used to point to, according to the report [5].

The lapsed domains and the permission test are separate findings in the report as Infosecurity describes it [5][6]. Put together, they lead from a domain purchase to a read of a project's secrets file. "A malicious MCP server first asked for access to a harmless file. The user approved it with an always-allow permission," the report said [7]. "The server then requested a sensitive file, .env among them, and got it, with no further prompt required" [8]. Anthropic's reply, as Ox relays it, leaves the user's always-allow grant as the only control in that sequence, because Anthropic does not treat model-level detection as a security boundary [9].

The geography finding is about jurisdiction. About 800 unique hostnames resolved outside the US, in countries including Russia and China [2][1]. The report's title counts 15,465 servers across mcp-official-registry, cline-marketplace and github-mcp-registry [1]. That is roughly three server entries per unique hostname [3]. Infosecurity's account does not say whether any of the offshore servers is hostile. For residency, location is enough. Regulated data sent to a server in another country can breach a commitment no matter who runs the server. "MCP has no protocol-level concept of geographic region," the report said [3]. "An enterprise can enforce strict residency controls on its own cloud workloads while its AI agents connect freely to servers sitting outside those same controls" [4].

With no region in the protocol, residency has to be enforced on the outbound connection. That means a list of MCP hostnames an agent may reach, checked in the client configuration and again at network egress. Cloud policy covers where a company's own workloads run [4]. An agent picking a tool from a public registry is outside that policy. A hostname allowlist also inherits the lapsed-domain problem. A name that was approved, expires and is re-registered by someone else stays approved until someone removes it [5].

Ox's April 2026 report came after Backslash Security's June 2025 NeighborJack findings [10]. It described a "critical, systemic" vulnerability allowing arbitrary command execution [11]. Ox called it "an architectural design decision baked into Anthropic's official MCP SDKs across every supported programming language" [13]. The vendor put exposure at as many as 200 open-source projects, 150 million downloads and up to 200,000 vulnerable instances, all upper bounds it set itself [12]. Anthropic dismissed that report as "expected behavior," leaving fixes to the individual open-source projects it affects [14].

What to watch

  • Whether mcp-official-registry, cline-marketplace and github-mcp-registry delist entries whose hostnames no longer resolve, and whether any lapsed names Ox flagged get re-registered.
  • Whether Anthropic narrows always-allow in Claude Code to per-file or per-session scope after answering both Ox reports that the behavior is intended.
  • Whether any of the three registries adds hosting location to server listings, so clients could filter by region.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories