MCP生态存在严重安全漏洞,攻击者可伪造工具诱导大模型执行恶意操作。
A First Look at the Security Issues in the Model Context Protocol Ecosystem
- 通过注册表级漏洞入侵,伪造工具元数据操控大模型推理
- 分析6.7万服务器发现普遍存在劫持与调用篡改风险
- 开发检测工具MCPInspect,识别833个易受攻击服务
模型上下文协议(MCP)作为连接大语言模型与外部工具的标准,其生态系统在主机、服务器和注册表层面引入了新的安全风险。本文首次开展跨实体的MCP安全研究,采用两阶段攻击面分析。在注册表层面,薄弱的审核与所有权验证机制允许恶意或被劫持的服务器接入主机。集成后,攻击者控制的工具元数据可影响大模型推理并诱导其执行恶意操作,而主机缺乏独立验证。代码级漏洞(如代码注入)虽非必需,但可放大攻击参数实现利用。我们分析了六个公开注册表中的67,057个服务器,发现普遍存在服务器劫持与调用操纵条件。进一步开发了MCPInspect预集成分析工具,可检测误导性工具元数据及可利用的代码漏洞,共识别出833个易受攻击服务器和18个描述可疑的服务。
原文摘要 · Abstract (English)
The Model Context Protocol (MCP) has emerged as a standard for connecting large language models (LLMs) with external tools. However, this MCP ecosystem introduces new security risks across hosts, servers, and registries. In this paper, we present the first cross-entity security study of MCP under a two-stage attack surface. At the registry-level, weak vetting and ownership checks allow adversarial or hijacked servers to enter hosts. After integration, attacker-controlled tool metadata can shape LLM reasoning and induce attacker-intended operations, which hosts execute without independent verification. Code-level vulnerabilities (e.g., code injection) are not required but can amplify attacker-controlled parameters into exploitation. We analyze 67,057 servers across six public registries and identify widespread conditions enabling server hijacking and invocation manipulation. We further implement MCPInspect, a pre-integration analysis tool that detects misleading tool metadata and exploitable code vulnerabilities, identifying 833 vulnerable servers and 18 with suspicious descriptions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。