MCP Security Crisis: 40+ CVEs, 36% SSRF Exposure, Prompt Injection at Scale
BlueRock Security analyzed 7,000+ public MCP servers: 36.7% have SSRF vulnerabilities, 41% require no authentication at all. Anthropic's own mcp-server-git shipped with 3 RCE-enabling flaws (quietly patched Jan 2026). OX Security disclosed a systemic RCE in MCP SDK stdio transport affecting all language SDKs and 150M+ downloads. Trend Micro found 492 MCP servers exposed with zero auth. Between Jan-Apr 2026, 40+ CVEs filed. A Reddit post on r/netsec about AI coding tools leaking secrets via config directories got 163 upvotes and 17 comments. The 'S in MCP stands for Security' article went HN-front-page.
A CLI tool that scans any public MCP server for SSRF, missing auth, and stdio RCE flaws before a developer adds it to their agent config
180 ▲Score Breakdown
Social Proof 2 sources
Gap Assessment
No standard auth enforcement layer, no universal MCP security scanner with >1k traction. mcp-scan and Backslash Security are early-stage. OWASP top 10 LLM ranks prompt injection #1 but no category-leader solution for MCP-specific security.