Fetching from the wire…
Security2026-06-19 · source-backed
A May 2026 OX Security disclosure flagged a systemic tool-poisoning weakness across MCP implementations with roughly 150M downloads and an estimated 200,000 vulnerable instances. Malicious instructions hide in server-side tool metadata the agent reads at boot but the user never sees. This is not prompt injection, which is an input-validation problem. The model literally cannot distinguish poisoned tool metadata from a legitimate prompt, so client-side defenses don't work. Put the fix on the network: tool allowlisting, identity binding, runtime monitoring, and human-in-the-loop checkpoints at an AI gateway. If you're wiring MCP connectors into anything that touches secrets, this is the threat model to design against first.
Each link below shares sources, entities, or timing with this story.
Claude uses MCP / Shared entity: MCP / Shared topic / What happened next / Tension
Linked by a graph relationship (Claude uses MCP); both cover MCP; overlapping topics (against, agent, prompt, tool).
OpenAI supports MCP / Shared entity: MCP / Shared topic / What happened next / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover MCP; overlapping topics (against, agent, model, tool).
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover MCP, OX Security; overlapping topics (agent, model, tool).
ChatGPT supports MCP / Shared entity: MCP / Shared topic / What happened next / Tension
Linked by a graph relationship (ChatGPT supports MCP); both cover MCP; overlapping topics (against, agent, tool).
Cursor uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cursor uses MCP); both cover Malicious, MCP; overlapping topics (agent, tool).
Cursor uses MCP / Shared entity: MCP / Shared topic / What happened next
Linked by a graph relationship (Cursor uses MCP); both cover MCP; overlapping topics (agent, cannot, model, prompt).
Anthropic released MCP / Shared entity: MCP / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Anthropic released MCP); both cover MCP; overlapping topics (agent, client-side, tool).
MCP uses OAuth / Shared entity: MCP / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP uses OAuth); both cover MCP; overlapping topics (against, agent, tool).