Skip to content
Hacker News front page

MCP hits a security inflection point: 21,000 servers exposed, 92% lack OAuth

21,000 MCP servers exposed: the protocol reaches a security inflection point

Over 21,000 internet-facing MCP servers were found, 91.8% of audited production instances missing OAuth, and 687 had unrestricted shell tool access. OWASP published an MCP Top 10, and more than 10 critical/high-severity CVEs are tracked. The core dispute: Anthropic says the STDIO transport behavior is 'by design' and input sanitization is the developer's job; OX Security and an arXiv paper call it a systemic architectural flaw affecting up to 150 million downstream package downloads. MCP governance moved to the Linux Foundation's Agentic AI Foundation, and the Aug 13–14 Seoul Dev Summit is the first in-person meeting between protocol designers and the security community to debate architectural hardening. The post does not disclose a fix timeline.

Why it matters: First quantified exposure data for MCP security, with OWASP releasing a risk framework in parallel—directly advances the protocol-layer security conversation for the agent ecosystem. Not scored higher because the article is a roundup of scan results without new vulnerability d...

Read the original ↗Export Markdown