Known MCP Vulnerabilities and How an MCP Gateway Blocks Them
TL;DR The Model Context Protocol introduces security vectors including tool poisoning, STDIO command injection, tool shadowing, and credential exfiltration. Multiple high-severity vulnerabilities (such as CVE-2025-54073 and CVE-2026-33032) demonstrate how unvalidated tool metadata and unsanitized transport parameters compromise host systems. Point-to-point connections between AI models and MCP…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.