Skip to main content
CybersecurityHacking

MCP Servers Expose Enterprises to Unvetted Risks

Rows of computer servers in a brightly-lit data center with technicians working in the background.

OX Security's researchers analyzed 15,465 publicly indexed MCP servers and deduplicated them to 5,095 unique hostnames, revealing an ecosystem built fast — and policed not at all.

The scale: 15,465 servers, 5,095 hostnames

In 2024 MCP (Model Context Protocol) aimed to be "the USB-C of AI": a single standard to connect models, agents, and IDEs to tools and data. Thousands of developers built servers and enterprises plugged them into agent workflows. OX Security's review of community-published servers across five MCP registries found 15,465 publicly indexed instances, deduplicated into 5,095 distinct hostnames — a snapshot of wide deployment without centralized governance.

MCP marketplaces: a marketplace with no bouncer

Unlike historical precedents such as Google's 2012 "Bouncer" automated scanner for Android apps, MCP marketplaces offer no equivalent screening. OX Security describes these registries bluntly: "no guardrails and no review." Anyone can write, push, and publish a server. The team notes that even code review is insufficient: remote MCP servers can run backend code that differs entirely from what their public repository shows. As OX Security put it in their earlier presentation "In GitHub We Trust: 10 Ways You Can Get Pwned," developers often over-trust repository contents; MCP repeats that mistake.

Where your data can go: jurisdictions, home networks, and reclaimed identities

The location and ownership of MCP endpoints matter because agents forward real requests and data to them. OX Security's findings include:

  • 15.6% of hostnames resolve to infrastructure outside the United States — including 19 that resolve to China and 18 that resolve to Russia. That means an agent connected to these servers may send data to jurisdictions the security team never approved.
  • 0.45% of servers route traffic through consumer tunneling services, mainly ngrok-free, indicating these publicly listed servers run from personal machines and likely home networks.
  • 2.3% of hostnames no longer resolve; six of those sit on expired domains that anyone can register for $4 to $12 a year. A new owner could inherit an established server identity — and requests from any agent still configured to call it.

OX Security also warns that location and routing can change: an operator could launch a server on a clean U.S. IP address and later route traffic somewhere else, altering the data residency and threat profile after initial deployment.

Trust is the attack surface: code signing, origin verification, and missing controls

OX Security emphasizes the protocol is not itself the problem; the problem is the trust placed in unvetted servers. Their recommendation is clear: until marketplaces add vetting, code signing, and origin verification, enterprises must take on that work. The full report includes methodology, a prompt-injection proof-of-concept, and threat scenarios tied to each finding — illustrating how misplaced trust expands the attack surface.

What this means for technologists and security teams, procurement leaders, and adversaries

  • Technologists and security teams: The report underscores that existing cloud governance — data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits — cannot be assumed to extend automatically to external MCP connections. Teams will need to treat MCP endpoints as third-party services and add vetting and origin verification where marketplaces do not.
  • Affected enterprises and procurement leaders: Enterprises that have "plugged [MCP servers] into agent workflows" must inventory which agents call external servers, assess hostnames against the report's findings (notably non‑U.S. jurisdictions and tunneling services), and address dangling domains that could be re-registered for as little as $4–$12 per year.
  • Adversaries and opportunistic operators: The study highlights low-cost, high-impact paths for abuse: registering expired domains to inherit server identities, exploiting personal‑machine endpoints routed through consumer tunnels, or changing server routing after initial trust is established. OX Security's earlier work tracing critical vulnerabilities in Anthropic's MCP source code — downloaded more than 150 million times — underscores how supply-chain and distribution paths amplify risk.

Report, proof-of-concept, and the next public briefing

OX Security's full write-up — titled "15,465 MCP Servers, 0 Governance" — includes their methodology, a prompt-injection proof-of-concept, and mapped threat scenarios. The team is also holding a live webinar, "The AI Attack Surface Is Already in Your Cloud," on October 13 at 12:00 PM ET, featuring Latio founder and CEO James Berthoty and OX Field CTO Chris Lindsey to discuss how AI reshapes cloud threats and what security teams should do about it.

For organizations that have already wired agents to external MCP endpoints, the core choice is blunt: accept the current lack of marketplace vetting and build compensating controls, or demand that marketplaces add vetting, code signing, and origin verification so trust is earned before it is granted.

Original report