arXiv:2608.00150cs.CRcs.AI2026-08

首次对公开互联网的MCP服务器进行动态安全评估,发现大量高危漏洞。

Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale

  • 通过11个数据源+自研框架Corvus,动态测试414个生产级MCP服务器
  • 发现68个可报告漏洞,包括SQL注入、云元数据攻击等,91.8%无OAuth认证
  • 超六成工具暴露无控命令执行,近半服务器三天内消失,反映快速部署缺陷

自2024年11月发布以来,模型上下文协议(MCP)迅速普及,全球可探测到超过21,000个公开互联网上的服务器实例。本文首次开展面向公网MCP服务器的动态行为安全评估,结合十一项数据源(crt.sh、HuggingFace、GitHub、npm、Smithery、PyPI、Censys、FOFA、Shodan、glama.ai、pulsemcp.com)的被动发现与基于Corvus框架的主动动态测试,该框架包含34个测试模块,覆盖10类MCP特定漏洞。在2026年7月四轮测量中,确认640个生产环境服务器,动态审计414个,发现68个可报告漏洞,包括SQL注入、针对云元数据服务的SSRF、提示模板注入及通过游标操作实现的路径遍历。发现91.8%被审计服务器缺乏OAuth认证,687个工具实例暴露无访问控制的命令执行能力,41.6%已确认服务器在连续测量周期内三日内消失,表明存在快速迭代但无安全审查的部署模式。研究团队实施负责任披露流程,并开源Corvus框架以支持MCP安全评估。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) has seen rapid adoption since its November 2024 launch, with over 21,000 server instances detectable on the public internet. We present the first dynamic behavioral security assessment of internet-facing MCP servers, combining passive discovery across eleven data sources (crt.sh, HuggingFace, GitHub, npm, Smithery, PyPI, Censys, FOFA, Shodan, glama.ai, and pulsemcp.com) with active dynamic testing using Corvus, a purpose-built framework implementing 34 test modules covering 10 MCP-specific vulnerability classes. Across four measurement runs spanning July 2026, we confirm 640 production MCP servers and dynamically audit 414, uncovering 68 reportable vulnerabilities including SQL injection, SSRF targeting cloud metadata services, prompt template injection, and path traversal via cursor manipulation. We find that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles without security review. We report on our responsible disclosure pipeline and release Corvus as an open-source framework for MCP security evaluation.

MCP安全动态检测漏洞评估命令执行

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。