Agentic Security: Thousands of Exposed MCP Servers and One-Click RCE in Major Coding Agents
Adversa AI / Help Net Security·medium signal
June MCP-security roundups flag roughly 12,520 internet-exposed MCP services (about 40% unauthenticated), plus a wave of disclosures including VIPER-MCP's 67 CVEs and NSA design guidance. Adversa AI's TrustFall and SymJack show Claude Code, Cursor, Gemini CLI, Copilot CLI, Grok Build, and OpenAI Codex CLI can auto-execute project-defined MCP servers or overwrite their own config the moment a developer accepts a folder-trust prompt — yielding RCE with full user privileges. The throughline: agent approval prompts don't reflect what actually gets executed.