Nearly 16% of the 5,095 unique MCP hostnames Ox Security analyzed resolved outside the United States, including in Russia and China, the firm reported — a figure that crystallizes how a protocol designed to simplify AI integrations can sidestep enterprise controls.
Ox Security’s analysis and the headline figure
Ox Security’s report, 15,465 MCP Servers, 0 Governance, draws on registry data from three public sources: mcp-official-registry, cline-marketplace and github-mcp-registry. The report argues MCP (Model Context Protocol) servers create a "silent enterprise governance gap" by standardizing how AI applications connect to external tools and data so developers “don’t have to write custom code each time they want to connect AI to an API or database.”
From the dataset the researchers described, 5,095 unique hostnames were analyzed. Ox Security found that nearly 16% resolved to locations outside the US and that more than 2% of hostnames no longer resolved at all — some now unregistered and available for purchase, a situation the report says could allow a threat actor to impersonate servers they once pointed to.
Geographic exposure and the protocol’s limits
“MCP has no protocol-level concept of geographic region,” Ox Security warned, stressing that enterprises can enforce strict residency controls on cloud workloads while their AI agents “connect freely to servers sitting outside those same controls.” The report frames this as a concrete clash between MCP’s design and common organizational controls such as data residency requirements, zero trust boundaries, granular IAM policies and continuous supply-chain audits.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePermission behavior demonstrated with Claude Code and Haiku 3.5
Ox Security tested Anthropic’s Claude Code with Haiku 3.5 and reported a straightforward escalation path tied to a single permission decision. In the test, a malicious MCP server first requested access to a harmless file; the user approved that request with an “always-allow” permission. The server then requested a sensitive file, including .env, and received it without any further prompt.
Ox Security summarized Anthropic’s stance on that behavior: “once always-allow is granted, that’s the documented behavior, and model-level detection of malicious content is a best-effort heuristic, not a security boundary.” The report also notes the model maker dismissed a prior vendor report as “expected behavior,” and that the vendor left the AI supply chain to work on fixes to patch the individual open-source projects it impacts.
Related vulnerabilities: NeighborJack and the April 2026 finding
Ox Security’s new report sits atop a string of prior findings that paint a consistent picture of risk proliferation. A June 2025 analysis by Backslash Security of some 7,000 MCP servers found hundreds exposed to anyone on the same local network through a vulnerability it called “NeighborJack.” That report identified around 70 servers with severe flaws, including unchecked input handling and excessive permissions.
In April 2026, Ox Security published an earlier report describing what it called a “critical, systemic” vulnerability in MCP that could enable arbitrary command execution on any vulnerable system. The vendor claimed the flaw affected as many as 200 open-source projects, had driven 150 million downloads, involved 7,000+ publicly accessible servers, and could expose up to 200,000 vulnerable instances. Ox Security framed that issue not as a traditional bug but as “an architectural design decision baked into Anthropic’s official MCP SDKs across every supported programming language.”
What this means for technologists, policymakers, and procurement leaders
- Technologists and security teams: Ox Security’s findings point to blind spots where established controls—data residency rules, zero-trust boundaries, IAM and supply-chain audits—can be circumvented by MCP connections resolving to external servers, including outside the enterprise’s expected jurisdictions.
- Policymakers and regulators: The report highlights a mismatch between protocol behavior and regulatory expectations about geographic controls and supply-chain integrity, underscoring a potential enforcement challenge when protocol-level concepts for region or residency do not exist.
- Procurement and enterprise leaders: The fact that some hostnames no longer resolve and are available for purchase raises a procurement and operational risk: services your agents rely on can be supplanted, and a single “always-allow” permission can widen access without further human review.
Ox Security’s work ties together registry observation, exploit demonstrations and prior vulnerability research into a single theme: MCP’s convenience — standardizing connections between models and external tooling — can create governance pathways around traditional enterprise and cloud security controls. With reports showing servers outside expected geographies, non-resolving hostnames now available to buy, an “always-allow” permission model that eliminates additional prompts, and earlier findings such as NeighborJack and the April 2026 architectural concern, the record presented in Ox Security’s report frames the gap as both technical and organizational.
The model maker’s description of the behavior as “expected” and its decision to leave patching to the AI supply chain leave open a practical question: can downstream fixes and open-source patches alone close a governance gap that some of Ox Security’s evidence ties directly to MCP’s protocol design? That is the question enterprises and regulators will now have to answer.
https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/




