AI Integration Tool 'MCP' Found Riddled with Governance Blind Spots
Researchers at Ox Security have warned that Model Context Protocol (MCP) servers, which allow AI applications to connect easily to external tools and data, are creating a hidden governance gap in enterprise cybersecurity. Analysing over 15,000 MCP servers across public registries, the firm found nearly 16% of unique hostnames resolved to locations outside the US, including Russia and China, despite MCP having no built in concept of geographic region or data residency controls.
The report also found that more than 2% of analysed hostnames no longer resolved at all, meaning some domains were unregistered and could be bought by attackers to impersonate legitimate servers. Separately, testing on an AI coding assistant showed that once a user granted a single 'always-allow' permission to a server, it could then request and receive sensitive files, such as configuration files containing secrets, without further approval. This mirrors earlier findings from Backslash Security in June 2025, which identified hundreds of MCP servers exposed to local network attacks, some with severe flaws such as poor input validation and excessive permissions.
Together, these findings suggest that as businesses rapidly adopt AI tools built on MCP, security oversight is lagging well behind adoption, leaving gaps that traditional cloud security controls were designed to prevent.