Skip to content

Topic

Model Context Protocol Security

The field of securing Model Context Protocol (MCP) servers and clients against auth flaws, injection attacks, and unsafe command execution.

Current stories

build1 publisher

One COPY line runs a shell despite AWS's read-only Postgres MCP filter

AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives40
Confidence50

Earlier coverage

  1. MCP is four trust boundaries, and credentials only close one of them

    Build · August 23, 2026 · 1 publisher

  2. Google names the default posture for agent security, and boards will borrow the words

    Leadership · August 22, 2026 · 1 publisher

  3. Exposed MCP servers are now a scanned entry point, and N4D's agent calls the tools itself

    Science · August 21, 2026 · 1 publisher

  4. OX Security says MCP command execution is a design choice, so server owners own the risk

    Science · August 19, 2026 · 1 publisher

  5. Human-in-the-loop is being retired, and the assurance burden shifts to machine identity

    Leadership · August 18, 2026 · 1 publisher

  6. The credential store nobody inventoried: MCP servers now hold the keys to everything they touch

    Security · August 18, 2026 · 1 publisher

  7. Microsoft ships an MIT-licensed agent kernel: policy rings, Ed25519 identity, kill switch

    Build · August 17, 2026 · 1 publisher