NSA Warns on MCP Security Gaps — and Three SDK CVEs Prove the Point

identity access free stock image for MCPwatch editorial use

The NSA AISC published the first government cybersecurity guidance on MCP, identifying inverted trust, unsigned tool descriptions, and missing authentication as structural gaps. Three CVEs in the official MCP SDKs — wildcard CORS in Java, JSON key smuggling in Go, and DNS rebinding before v0.25 — prove these are not theoretical risks.