Urgent.News

What's breaking now, across thousands of outlets.

Tech

I Built an MCP Server for Domain Investigation - 5 Security Gotchas I Hit

The CVE counter hit 30 before Valentine's Day The first CVE for an MCP server dropped on January 3. By February 14, the count was past thirty. I found that out while I was still debugging why my new MCP server had handed an AI agent a raw WHOIS record with a typo-squatted registrar name, and the agent treated it like gospel. That server wrapped my Portfolio Investigate API as an MCP tool. One…

In the week leading up to Valentine's Day, the count of Common Vulnerabilities and Exposures (CVEs) for MCP servers surpassed thirty. This was discovered by the author while debugging their new MCP server, which had transmitted an AI agent a raw WHOIS record with a typo-squatted registrar name. The MCP server served as a wrapper for the Portfolio Investigate API, providing a domain dossier that included WHOIS data, IP geolocation, company information, email reputation, sanctions screening, and a verdict.

The developer, who thought they were merely wrapping a REST API, realized they had inadvertently created an attack surface. The Python server responsible for this functionality utilized the FastMCP library and interacted with the Portfolio Investigate API using asynchronous HTTP requests. Despite the server functioning initially, the developer later read the OWASP Top 10 for Agentic Applications, which highlighted numerous security concerns related to agentic applications.

The developer found that many open-source MCP servers required credentials, and a significant percentage of those used long-lived static secrets. Additionally, some public MCP servers granted tool access without authentication. This realization prompted the developer to harden their MCP server, opting to remove the static API key and replace it with OAuth 2.1 client credentials that issued short-lived access tokens.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 10 August →