Badges and Stars Don’t Protect MCP Servers: 4,982 Flaws in 9,695 Scanned
TrendAI studied 9,695 MCP servers: verified badges and GitHub stars don’t reduce vulnerability counts. 4,982 security issues found across 2,259 servers.
TrendAI studied 9,695 MCP servers: verified badges and GitHub stars don’t reduce vulnerability counts. 4,982 security issues found across 2,259 servers.
The NSA AISC published the first government cybersecurity guidance on MCP, identifying inverted trust, unsigned tool descriptions, and missing authentication as structural gaps. Three CVEs in the official MCP SDKs — wildcard CORS in Java, JSON key smuggling in Go, and DNS rebinding before v0.25 — prove these are not theoretical risks.
Wiz discovered CVE-2026-12957 in Amazon Q Developer (CVSS 8.5): opening a repo auto-executes MCP configs, handing cloud credentials to attackers. The same week, Tenet Security disclosed Agentjacking — an 85% success rate attack class using fake Sentry errors to hijack AI coding agents via MCP. Combined with new CVEs in chrome-devtools-mcp and OpenClaw, the developer-tool attack surface for MCP is widening fast.
An analytical overview of the first wave of MCP incidents, CVEs, malicious packages, and operator lessons.