设计暴露:面向互联网的MCP服务器的大规模动态安全评估
Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale
- CobaltoSec(科巴尔特安全公司)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
该研究针对公共互联网上的MCP服务器开展大规模动态安全评估,借助自主框架Corvus发现大量未授权、存在漏洞的服务器,并开源Corvus用于MCP安全评估。
AI中文摘要:
模型上下文协议(Model Context Protocol,MCP)自2024年11月推出以来被快速采用,公共互联网上可检测到超过21000个服务器实例。我们开展了首个面向互联网的MCP服务器动态行为安全评估,整合了11个数据源(包括该链接、HuggingFace、GitHub、npm、Smithery、PyPI、Censys、FOFA、Shodan、该链接、该链接)的被动发现,以及使用专用框架Corvus的主动动态测试,Corvus实现了34个测试模块,覆盖10类MCP特有漏洞。在2026年7月的四次测量运行中,我们确认了640个生产环境MCP服务器,对其中414个进行了动态审计,发现了68个可报告漏洞,包括SQL注入、针对云元数据服务的SSRF、提示模板注入以及通过光标操作的路径遍历。我们发现,91.8%的接受动态审计的服务器缺乏OAuth认证,已确认服务器中的687个工具实例在无访问控制的情况下暴露了Shell执行能力,且41.6%的已确认服务器在连续测量运行之间的三天内消失,表明存在未经过安全审查的快速部署周期。我们报告了我们的负责任披露流程,并将Corvus作为用于MCP安全评估的开源框架发布。
英文摘要:
The Model Context Protocol (MCP) has seen rapid adoption since its November 2024 launch, with over 21,000 server instances detectable on the public internet. We present the first dynamic behavioral security assessment of internet-facing MCP servers, combining passive discovery across eleven data sources (crt.sh, HuggingFace, GitHub, npm, Smithery, PyPI, Censys, FOFA, Shodan, glama.ai, and pulsemcp.com) with active dynamic testing using Corvus, a purpose-built framework implementing 34 test modules covering 10 MCP-specific vulnerability classes. Across four measurement runs spanning July 2026, we confirm 640 production MCP servers and dynamically audit 414, uncovering 68 reportable vulnerabilities including SQL injection, SSRF targeting cloud metadata services, prompt template injection, and path traversal via cursor manipulation. We find that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles without security review. We report on our responsible disclosure pipeline and release Corvus as an open-source framework for MCP security evaluation.