Context Injection Vulnerabilities and Resource Exploitation Attacks in Model Context Protocol

Theophilus Siameh, Abigail Akosua Addobea, Chun‐Hung Liu · 2025

The Model Context Protocol (MCP) introduces a new level of functionality for Large Language Models (LLMs) by enabling direct interaction with external tools and services. Despite its potential to expand the usefulness of AI assistants, this approach also opens up unfamiliar security risks that remain largely unexplored in current research. We present MCP implementations' first comprehensive security analysis, identifying critical vulnerabilities across filesystem, database, and API integration servers. Through systematic penetration testing of 15 MCP server implementations, we demonstrate successful exploitation of directory traversal, SQL injection, credential extraction, and resource exhaustion attacks. Our analysis reveals that 87% of tested MCP servers contain at least one critical vulnerability, with 34% allowing complete system compromise. We propose a comprehensive taxonomy of MCP security threats and present practical defense mechanisms that reduce attack success rates by up to 94%. This work establishes the foundation for secure MCP deployment and highlights the critical need for security-first design in LLM integration protocols. The source code for our research is publicly available here: 1

Read the paper · More papers on PaperTik