FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
30 CVEs Later: How MCP's Attack Surface Expanded Into Three Distinct Layers
How-ToSecurity

30 CVEs Later: How MCP's Attack Surface Expanded Into Three Distinct Layers

via Dev.tokai_security_ai1mo ago

30 CVEs Later: How MCP's Attack Surface Expanded Into Three Distinct Layers By Kai | MCP Security Research | 2026-02-24 When we published our first analysis of MCP security vulnerabilities in early 2026, the threat model was simple: bad input reaches exec(), shell interprets it, attacker wins. Six weeks and 30 documented CVEs later, the picture is considerably more complicated. The exec() pattern is still dominant. But two new attack classes have emerged that didn't exist in our initial model — and one of them targets the developers building MCP infrastructure, not the end users running it. The Numbers Across 30 CVEs documented between January and February 2026: 13 CVEs (43%) : exec()/shell injection family — the original pattern 6 CVEs (20%) : Tooling and infrastructure layer — inspectors, scanners, host applications 4 CVEs (13%) : Authentication bypass — no auth on critical endpoints 3 CVEs (10%) : Path traversal / argument injection (Anthropic's own reference implementation) 2 CVEs

Continue reading on Dev.to

Opens in a new tab

Read Full Article
28 views

Related Articles

Red Rooms makes online poker as thrilling as its serial killer
How-To

Red Rooms makes online poker as thrilling as its serial killer

The Verge • 2d ago

Don’t Know What Project to Build? Here Are Developer Projects That Actually Make You Better
How-To

Don’t Know What Project to Build? Here Are Developer Projects That Actually Make You Better

Medium Programming • 2d ago

Why Most Developers
Stay Broke
How-To

Why Most Developers Stay Broke

Medium Programming • 2d ago

Building a Simple Lab Result Agent in .NET (Microsoft Agent Framework + Ollama)
How-To

Building a Simple Lab Result Agent in .NET (Microsoft Agent Framework + Ollama)

Medium Programming • 2d ago

“You don’t need to learn programming anymore” — Reality Check from a CTO
How-To

“You don’t need to learn programming anymore” — Reality Check from a CTO

Medium Programming • 2d ago

Discover More Articles