Fetching from the wire…
Public story · 2026-09-15 · high
A census of the public MCP registry found 4.2% of servers redirect to a different host without any way for installed clients to notice.
Why now: The findings cover an August 2026 snapshot of the full registry, published to arXiv as 2609.14119.
Researchers pulled the entire public MCP registry, 21,643 servers and 72,606 version records, and fetched source for 14,353 of them. They ran each one against an eight-class threat catalogue built from 414 hand-labeled findings. Among servers with more than one version, 51.1% changed what they advertise between releases, and 40.6% did it with no changelog signal a client could act on.
The part that should worry anyone pinning a server by version string: 4.2% repointed their remote endpoint to a different host while keeping the same registry identity. The MCP registry census found the protocol has no mechanism to push that change to anything already installed. A client that approved version 1.0 has no signal that version 1.3 now talks to a different backend entirely.
Silence tracks with danger. Servers that changed their advertised surface without a visible signal carried almost three times the odds of a high-severity finding, an odds ratio of 2.96 with a 95% confidence interval of 2.56 to 3.42. Star count barely helps: each additional log-star cut the odds by only 22%, an odds ratio of 0.78. A well-starred server can still drift into a high-severity change with nothing to flag it.
The paper doesn't say whether any registry operator is building endpoint-change alerts in response, or whether this behavior clusters in a small set of publishers rather than spreading across the ecosystem. Until something like that exists, treating a pinned MCP version as static is a bet, not a fact.
Each link below shares sources, entities, or timing with this story.
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The errors trace back to how the benchmark pairs pull requests with GitHub issues, not just to model quality.
A trained failure monitor's accuracy collapses on a new model; a simple arithmetic check doesn't budge.
An attacker stole an AI agent's signing keys through email injection in under five minutes, per a prior incident this design cites.
Across 46 model endpoints, block rates on the same forged-command test swing up to 47 points between configurations.
A training-free fix called ChannelGuard held steady across three model backends, filter or no filter, blocking every tool-poisoning attempt.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.