Fetching from the wire…
Public story · 2026-08-17 · high
Five simulated attacks show NASA's flight software lets one rogue component abuse shared authority undetected, a design flaw MCP repeats.
Why now: The paper surfaced in the August 17 briefing, as AI teams wire MCP servers into agents with the same shared-permission design it flags.
A malicious component compromised NASA's flight software without breaking a single access rule, per a new architectural analysis (arXiv 2608.14532). Five experiments on NASA's flight-representative NOS3 simulator confirmed the attack works using only legitimate architectural privileges. The same trust assumptions turn up in other modular flight software frameworks too, per the analysis, so the flaw isn't limited to NASA's code.
Core Flight Software gives every onboard component broad, shared authority over identity, communication, observability and persistence, per the analysis. A single compromised component can abuse that authority in ways the analysis found difficult to separate from legitimate behavior.
That architecture looks familiar outside aerospace. MCP, the protocol AI agents use to connect tools, hands every connected component the same broad permissions as the host process. A calendar plugin and a file-deletion plugin get treated the same way. Nobody has to write a bug to abuse that. They just have to be a plugin.
Each link below shares sources, entities, or timing with this story.
Claude Code uses MCP / Shared entity: MCP / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Claude Code uses MCP); both cover MCP; reported by the same outlet (arxiv.org).
Anthropic released MCP / Shared entity: MCP / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Anthropic released MCP); both cover MCP; reported by the same outlet (arxiv.org).
Anthropic released MCP / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover MCP; reported by the same outlet (arxiv.org).
Cursor uses MCP / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (Cursor uses MCP); both cover MCP; reported by the same outlet (arxiv.org).
OpenAI supports MCP / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover MCP; reported by the same outlet (arxiv.org).
MCP deprecates Logging / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (MCP deprecates Logging); both cover MCP; reported by the same outlet (arxiv.org).
Claude Code uses MCP / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover MCP; reported by the same outlet (arxiv.org).
Codex CLI uses MCP / Shared entity: MCP / Same source domain / Earlier coverage
Linked by a graph relationship (Codex CLI uses MCP); both cover MCP; reported by the same outlet (arxiv.org).