{
  "packageTitle": "MCP Security: Threats, Vulnerabilities, and How to Secure MCP Servers",
  "researchFreeze": "2026-08-25",
  "protocolRevision": "2026-07-28",
  "canonicalPage": "/mcp-security/",
  "status": "integrated-from-13-supplied-artifacts-with-disclosed-transfer-gaps",
  "suppliedArtifactCount": 13,
  "transferNamingNote": "The README uses generic archive names such as article.md; the transferred files use the MCP_SECURITY_ prefix.",
  "archiveLimitations": [
    "No checksum or file manifest was supplied, so byte-exact archive completeness cannot be established.",
    "The README names methodology_and_update_policy.md, quality_audit.md, build_data.py, and finalize_package.py, but those files were not supplied.",
    "The article describes additional matrices, registers, audits, and a 35-item myth audit that were not supplied as standalone artifacts."
  ],
  "artifacts": [
    {
      "file": "MCP_SECURITY_ARTICLE.html",
      "status": "supplied",
      "use": "Supplied standalone derivative retained for provenance; not published directly because the site renderer supplies canonical layout and metadata."
    },
    {
      "file": "MCP_SECURITY_ARTICLE.md",
      "status": "supplied",
      "use": "Canonical cornerstone source rendered at build time with citation reconciliation, visible FAQ, visuals, datasets, and internal links."
    },
    {
      "file": "MCP_SECURITY_BIBLIOGRAPHY.md",
      "status": "supplied",
      "use": "Bibliography coverage validation for all package-local evidence IDs and URLs."
    },
    {
      "file": "MCP_SECURITY_CLAIM_REGISTER.csv",
      "status": "supplied",
      "use": "Normalized 98-claim public dataset with package and canonical source IDs."
    },
    {
      "file": "MCP_SECURITY_CONTENT_CLUSTER.csv",
      "status": "supplied",
      "use": "Ranked 71-brief content plan and unified roadmap input with cannibalization reconciliation."
    },
    {
      "file": "MCP_SECURITY_EVIDENCE_MANIFEST.csv",
      "status": "supplied",
      "use": "Cross-format evidence validation and transfer-preserved source data."
    },
    {
      "file": "MCP_SECURITY_EVIDENCE_MANIFEST.json",
      "status": "supplied",
      "use": "Canonical evidence merge input for the public source library."
    },
    {
      "file": "MCP_SECURITY_FAQ.md",
      "status": "supplied",
      "use": "Fifty reader-facing FAQ answers rendered visibly and published as structured data."
    },
    {
      "file": "MCP_SECURITY_README.md",
      "status": "supplied",
      "use": "Package provenance, declared counts, live-check warning, and transfer-gap audit."
    },
    {
      "file": "MCP_SECURITY_SEO_PACKAGE.md",
      "status": "supplied",
      "use": "Canonical metadata, intent ownership, internal-link plan, structured data, and update cadence."
    },
    {
      "file": "MCP_SECURITY_VISUAL_SPECS.md",
      "status": "supplied",
      "use": "Fifteen normalized visual briefs implemented as SVG or native semantic article representations."
    },
    {
      "file": "MCP_SECURITY_VULNERABILITY_TIMELINE.csv",
      "status": "supplied",
      "use": "Chronologically normalized 48-record advisory dataset."
    },
    {
      "file": "MCP_SECURITY_VULNERABILITY_TIMELINE.md",
      "status": "supplied",
      "use": "Human-readable package timeline used for cross-format coverage validation."
    }
  ],
  "sourceMap": [
    {
      "packageSourceId": "SEC001",
      "canonicalSourceId": "S021",
      "url": "https://www.anthropic.com/news/model-context-protocol"
    },
    {
      "packageSourceId": "SEC002",
      "canonicalSourceId": "S024",
      "url": "https://modelcontextprotocol.io/specification/2024-11-05"
    },
    {
      "packageSourceId": "SEC003",
      "canonicalSourceId": "S027",
      "url": "https://modelcontextprotocol.io/specification/2024-11-05/basic/transports"
    },
    {
      "packageSourceId": "SEC004",
      "canonicalSourceId": "S028",
      "url": "https://modelcontextprotocol.io/specification/2024-11-05/server/tools"
    },
    {
      "packageSourceId": "SEC005",
      "canonicalSourceId": "S029",
      "url": "https://modelcontextprotocol.io/specification/2024-11-05/server/resources"
    },
    {
      "packageSourceId": "SEC006",
      "canonicalSourceId": "S032",
      "url": "https://modelcontextprotocol.io/specification/2024-11-05/client/sampling"
    },
    {
      "packageSourceId": "SEC007",
      "canonicalSourceId": "S036",
      "url": "https://modelcontextprotocol.io/specification/2025-03-26/changelog"
    },
    {
      "packageSourceId": "SEC008",
      "canonicalSourceId": "S037",
      "url": "https://modelcontextprotocol.io/specification/2025-03-26/basic/authorization"
    },
    {
      "packageSourceId": "SEC009",
      "canonicalSourceId": "S158",
      "url": "https://modelcontextprotocol.io/specification/2025-03-26/server/tools"
    },
    {
      "packageSourceId": "SEC010",
      "canonicalSourceId": "S043",
      "url": "https://modelcontextprotocol.io/specification/2025-06-18/changelog"
    },
    {
      "packageSourceId": "SEC011",
      "canonicalSourceId": "S044",
      "url": "https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization"
    },
    {
      "packageSourceId": "SEC012",
      "canonicalSourceId": "S049",
      "url": "https://modelcontextprotocol.io/specification/2025-11-25/changelog"
    },
    {
      "packageSourceId": "SEC013",
      "canonicalSourceId": "S187",
      "url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization"
    },
    {
      "packageSourceId": "SEC014",
      "canonicalSourceId": "S055",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/changelog"
    },
    {
      "packageSourceId": "SEC015",
      "canonicalSourceId": "S133",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization"
    },
    {
      "packageSourceId": "SEC016",
      "canonicalSourceId": "S134",
      "url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices"
    },
    {
      "packageSourceId": "SEC017",
      "canonicalSourceId": "S123",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/server/tools"
    },
    {
      "packageSourceId": "SEC018",
      "canonicalSourceId": "S057",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/transports#streamable-http"
    },
    {
      "packageSourceId": "SEC019",
      "canonicalSourceId": "S056",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/versioning"
    },
    {
      "packageSourceId": "SEC020",
      "canonicalSourceId": "S136",
      "url": "https://modelcontextprotocol.io/extensions/apps/overview"
    },
    {
      "packageSourceId": "SEC021",
      "canonicalSourceId": "S137",
      "url": "https://modelcontextprotocol.io/extensions/tasks/overview"
    },
    {
      "packageSourceId": "SEC022",
      "canonicalSourceId": "S064",
      "url": "https://blog.modelcontextprotocol.io/posts/mcp-roadmap/"
    },
    {
      "packageSourceId": "SEC023",
      "canonicalSourceId": "S058",
      "url": "https://blog.modelcontextprotocol.io/posts/2026-07-28/"
    },
    {
      "packageSourceId": "SEC024",
      "canonicalSourceId": "S053",
      "url": "https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/"
    },
    {
      "packageSourceId": "SEC025",
      "canonicalSourceId": "S188",
      "url": "https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf"
    },
    {
      "packageSourceId": "SEC026",
      "canonicalSourceId": "S189",
      "url": "https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496698/nsa-releases-security-design-considerations-for-ai-driven-automation-leveraging/"
    },
    {
      "packageSourceId": "SEC027",
      "canonicalSourceId": "S190",
      "url": "https://owasp.org/www-project-mcp-top-10/"
    },
    {
      "packageSourceId": "SEC028",
      "canonicalSourceId": "S191",
      "url": "https://www.rfc-editor.org/rfc/rfc9700"
    },
    {
      "packageSourceId": "SEC029",
      "canonicalSourceId": "S006",
      "url": "https://www.rfc-editor.org/rfc/rfc9728"
    },
    {
      "packageSourceId": "SEC030",
      "canonicalSourceId": "S005",
      "url": "https://www.rfc-editor.org/rfc/rfc8707"
    },
    {
      "packageSourceId": "SEC031",
      "canonicalSourceId": "S192",
      "url": "https://www.rfc-editor.org/rfc/rfc9207"
    },
    {
      "packageSourceId": "SEC032",
      "canonicalSourceId": "S004",
      "url": "https://www.rfc-editor.org/rfc/rfc7636"
    },
    {
      "packageSourceId": "SEC033",
      "canonicalSourceId": "S193",
      "url": "https://www.rfc-editor.org/rfc/rfc6750"
    },
    {
      "packageSourceId": "SEC034",
      "canonicalSourceId": "S194",
      "url": "https://www.rfc-editor.org/rfc/rfc7591"
    },
    {
      "packageSourceId": "SEC035",
      "canonicalSourceId": "S108",
      "url": "https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks"
    },
    {
      "packageSourceId": "SEC036",
      "canonicalSourceId": "S195",
      "url": "https://invariantlabs.ai/blog/whatsapp-mcp-exploited"
    },
    {
      "packageSourceId": "SEC037",
      "canonicalSourceId": "S196",
      "url": "https://arxiv.org/abs/2605.22333"
    },
    {
      "packageSourceId": "SEC038",
      "canonicalSourceId": "S197",
      "url": "https://arxiv.org/abs/2605.21392"
    },
    {
      "packageSourceId": "SEC039",
      "canonicalSourceId": "S198",
      "url": "https://doi.org/10.3390/jcp6030084"
    },
    {
      "packageSourceId": "SEC040",
      "canonicalSourceId": "S199",
      "url": "https://arxiv.org/abs/2603.18063"
    },
    {
      "packageSourceId": "SEC041",
      "canonicalSourceId": "S200",
      "url": "https://arxiv.org/abs/2512.06556"
    },
    {
      "packageSourceId": "SEC042",
      "canonicalSourceId": "S201",
      "url": "https://arxiv.org/abs/2601.07395"
    },
    {
      "packageSourceId": "SEC043",
      "canonicalSourceId": "S202",
      "url": "https://arxiv.org/abs/2606.27027"
    },
    {
      "packageSourceId": "SEC044",
      "canonicalSourceId": "S203",
      "url": "https://arxiv.org/abs/2604.17125"
    },
    {
      "packageSourceId": "SEC045",
      "canonicalSourceId": "S204",
      "url": "https://arxiv.org/abs/2608.00150"
    },
    {
      "packageSourceId": "SEC046",
      "canonicalSourceId": "S109",
      "url": "https://github.com/advisories/GHSA-7f8r-222p-6f5g"
    },
    {
      "packageSourceId": "SEC047",
      "canonicalSourceId": "S110",
      "url": "https://github.com/advisories/GHSA-g9hg-qhmf-q45m"
    },
    {
      "packageSourceId": "SEC048",
      "canonicalSourceId": "S205",
      "url": "https://github.com/advisories/GHSA-3qhf-m339-9g5v"
    },
    {
      "packageSourceId": "SEC049",
      "canonicalSourceId": "S206",
      "url": "https://github.com/advisories/GHSA-j975-95f5-7wqh"
    },
    {
      "packageSourceId": "SEC050",
      "canonicalSourceId": "S111",
      "url": "https://github.com/advisories/GHSA-w48q-cv73-mx4w"
    },
    {
      "packageSourceId": "SEC051",
      "canonicalSourceId": "S112",
      "url": "https://github.com/advisories/GHSA-9h52-p55h-vw2f"
    },
    {
      "packageSourceId": "SEC052",
      "canonicalSourceId": "S207",
      "url": "https://github.com/advisories/GHSA-xw59-hvm2-8pj6"
    },
    {
      "packageSourceId": "SEC053",
      "canonicalSourceId": "S208",
      "url": "https://github.com/advisories/GHSA-8jxr-pr72-r468"
    },
    {
      "packageSourceId": "SEC054",
      "canonicalSourceId": "S209",
      "url": "https://github.com/advisories/GHSA-89vp-x53w-74fx"
    },
    {
      "packageSourceId": "SEC055",
      "canonicalSourceId": "S210",
      "url": "https://github.com/advisories/GHSA-rjr6-rcgv-9m7m"
    },
    {
      "packageSourceId": "SEC056",
      "canonicalSourceId": "S211",
      "url": "https://github.com/advisories/GHSA-5p9g-j988-pcwv"
    },
    {
      "packageSourceId": "SEC057",
      "canonicalSourceId": "S212",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67430"
    },
    {
      "packageSourceId": "SEC058",
      "canonicalSourceId": "S213",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67432"
    },
    {
      "packageSourceId": "SEC059",
      "canonicalSourceId": "S214",
      "url": "https://github.com/advisories/GHSA-cqwc-fm46-7fff"
    },
    {
      "packageSourceId": "SEC060",
      "canonicalSourceId": "S147",
      "url": "https://github.com/advisories/GHSA-345p-7cg4-v4c7"
    },
    {
      "packageSourceId": "SEC061",
      "canonicalSourceId": "S215",
      "url": "https://github.com/advisories/GHSA-5cgr-j3jf-jw3v"
    },
    {
      "packageSourceId": "SEC062",
      "canonicalSourceId": "S216",
      "url": "https://github.com/advisories/GHSA-r48c-v28r-pf6v"
    },
    {
      "packageSourceId": "SEC063",
      "canonicalSourceId": "S217",
      "url": "https://github.com/advisories/GHSA-95c3-6vvw-4mrq"
    },
    {
      "packageSourceId": "SEC064",
      "canonicalSourceId": "S218",
      "url": "https://github.com/advisories/GHSA-v8vw-gw5j-w7m6"
    },
    {
      "packageSourceId": "SEC065",
      "canonicalSourceId": "S219",
      "url": "https://github.com/advisories/GHSA-rqv2-m695-f8j4"
    },
    {
      "packageSourceId": "SEC066",
      "canonicalSourceId": "S220",
      "url": "https://github.com/advisories/GHSA-2v5f-5r6w-p67r"
    },
    {
      "packageSourceId": "SEC067",
      "canonicalSourceId": "S221",
      "url": "https://github.com/advisories/GHSA-6fg3-hvw7-2fwq"
    },
    {
      "packageSourceId": "SEC068",
      "canonicalSourceId": "S222",
      "url": "https://github.com/advisories/GHSA-7pf3-8xx7-rvhf"
    },
    {
      "packageSourceId": "SEC069",
      "canonicalSourceId": "S223",
      "url": "https://github.com/advisories/GHSA-jwj7-74jh-p5c4"
    },
    {
      "packageSourceId": "SEC070",
      "canonicalSourceId": "S224",
      "url": "https://github.com/advisories/GHSA-232v-j27c-5pp6"
    },
    {
      "packageSourceId": "SEC071",
      "canonicalSourceId": "S225",
      "url": "https://github.com/advisories/GHSA-rww4-4w9c-7733"
    },
    {
      "packageSourceId": "SEC072",
      "canonicalSourceId": "S226",
      "url": "https://github.com/advisories/GHSA-73cv-556c-w3g6"
    },
    {
      "packageSourceId": "SEC073",
      "canonicalSourceId": "S227",
      "url": "https://github.com/advisories/GHSA-w4q6-qw23-4rg7"
    },
    {
      "packageSourceId": "SEC074",
      "canonicalSourceId": "S228",
      "url": "https://github.com/advisories/GHSA-pjp5-fpmr-3349"
    },
    {
      "packageSourceId": "SEC075",
      "canonicalSourceId": "S229",
      "url": "https://github.com/advisories/GHSA-cr22-wjx7-2w6m"
    },
    {
      "packageSourceId": "SEC076",
      "canonicalSourceId": "S230",
      "url": "https://github.com/advisories/GHSA-h9f9-h6gm-wc85"
    },
    {
      "packageSourceId": "SEC077",
      "canonicalSourceId": "S231",
      "url": "https://github.com/advisories/GHSA-mvq4-39wx-6h5g"
    },
    {
      "packageSourceId": "SEC078",
      "canonicalSourceId": "S232",
      "url": "https://github.com/advisories/GHSA-fgmx-xfp3-w28p"
    },
    {
      "packageSourceId": "SEC079",
      "canonicalSourceId": "S233",
      "url": "https://github.com/advisories/GHSA-8q5r-mmjf-575q"
    },
    {
      "packageSourceId": "SEC080",
      "canonicalSourceId": "S234",
      "url": "https://github.com/advisories/GHSA-6gr2-qh89-hxwm"
    },
    {
      "packageSourceId": "SEC081",
      "canonicalSourceId": "S235",
      "url": "https://github.com/advisories/GHSA-vf7j-7mrx-hp7g"
    },
    {
      "packageSourceId": "SEC082",
      "canonicalSourceId": "S236",
      "url": "https://github.com/advisories/GHSA-4pcc-j6m6-wcwx"
    },
    {
      "packageSourceId": "SEC083",
      "canonicalSourceId": "S237",
      "url": "https://github.com/advisories/GHSA-pmw7-gqwj-f954"
    },
    {
      "packageSourceId": "SEC084",
      "canonicalSourceId": "S238",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40159"
    },
    {
      "packageSourceId": "SEC085",
      "canonicalSourceId": "S239",
      "url": "https://github.com/advisories/GHSA-9qhq-v63v-fv3j"
    },
    {
      "packageSourceId": "SEC086",
      "canonicalSourceId": "S240",
      "url": "https://github.com/advisories/GHSA-p75f-6fp4-p57w"
    },
    {
      "packageSourceId": "SEC087",
      "canonicalSourceId": "S241",
      "url": "https://github.com/advisories/GHSA-9cr9-25q5-8prj"
    },
    {
      "packageSourceId": "SEC088",
      "canonicalSourceId": "S242",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33032"
    },
    {
      "packageSourceId": "SEC089",
      "canonicalSourceId": "S243",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6514"
    },
    {
      "packageSourceId": "SEC090",
      "canonicalSourceId": "S244",
      "url": "https://snyk.io/blog/postmark-mcp-server-backdoor/"
    },
    {
      "packageSourceId": "SEC091",
      "canonicalSourceId": "S245",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64109"
    },
    {
      "packageSourceId": "SEC092",
      "canonicalSourceId": "S246",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68433"
    },
    {
      "packageSourceId": "SEC093",
      "canonicalSourceId": "S247",
      "url": "https://github.com/advisories/GHSA-r6xh-pqhr-v4xh"
    },
    {
      "packageSourceId": "SEC094",
      "canonicalSourceId": "S066",
      "url": "https://blog.modelcontextprotocol.io/posts/2025-09-08-mcp-registry-preview/"
    },
    {
      "packageSourceId": "SEC095",
      "canonicalSourceId": "S067",
      "url": "https://modelcontextprotocol.io/registry/about"
    },
    {
      "packageSourceId": "SEC096",
      "canonicalSourceId": "S248",
      "url": "https://github.com/modelcontextprotocol/modelcontextprotocol/security/policy"
    }
  ],
  "articleCitations": {
    "packageSourceIds": [
      "SEC014",
      "SEC015",
      "SEC035",
      "SEC037",
      "SEC038",
      "SEC046",
      "SEC050",
      "SEC060",
      "SEC071",
      "SEC002",
      "SEC007",
      "SEC017",
      "SEC010",
      "SEC030",
      "SEC029",
      "SEC016",
      "SEC012",
      "SEC018",
      "SEC090",
      "SEC084",
      "SEC031",
      "SEC033",
      "SEC044",
      "SEC042",
      "SEC078",
      "SEC077",
      "SEC061",
      "SEC062",
      "SEC094",
      "SEC020",
      "SEC021",
      "SEC026",
      "SEC025",
      "SEC027",
      "SEC040",
      "SEC022"
    ],
    "canonicalSourceIds": [
      "S055",
      "S133",
      "S108",
      "S196",
      "S197",
      "S109",
      "S111",
      "S147",
      "S225",
      "S024",
      "S036",
      "S123",
      "S043",
      "S005",
      "S006",
      "S134",
      "S049",
      "S057",
      "S244",
      "S238",
      "S192",
      "S193",
      "S203",
      "S201",
      "S232",
      "S231",
      "S215",
      "S216",
      "S066",
      "S136",
      "S137",
      "S189",
      "S188",
      "S190",
      "S199",
      "S064"
    ],
    "count": 36
  },
  "counts": {
    "packageEvidence": 96,
    "claims": 98,
    "vulnerabilities": 48,
    "faqs": 50,
    "visualBriefs": 15,
    "supportingBriefs": 71,
    "unifiedRoadmapUrls": 161
  },
  "editorialCorrections": [
    "Two article links using unmanifested NVD alternates are normalized to their package-manifested GitHub advisory URLs while the raw draft remains unchanged.",
    "The public vulnerability dataset is sorted by disclosure date; package-local VULN046–VULN093 IDs preserve the supplied grouping order.",
    "The visible package inventory names only supplied artifacts and discloses README-referenced files that were absent from the transfer.",
    "The /is-mcp-secure/ and /mcp-security-faq/ briefs are reconciled to the cornerstone to enforce the supplied cannibalization guidance."
  ],
  "validationSignals": {
    "bibliographyMentionsEveryEvidenceId": true,
    "readmeDeclaresLiveCheck": true
  },
  "publicEndpoints": [
    "/mcp-security/",
    "/sources/",
    "/editorial-policy/",
    "/data/evidence.json",
    "/data/evidence.csv",
    "/data/mcp-security-claims.json",
    "/data/mcp-security-claims.csv",
    "/data/mcp-security-vulnerabilities.json",
    "/data/mcp-security-vulnerabilities.csv",
    "/data/mcp-security-faq.json",
    "/data/mcp-security-visuals.json",
    "/data/mcp-security-visuals.csv",
    "/data/mcp-security-content-plan.json",
    "/data/mcp-security-content-plan.csv",
    "/data/mcp-content-roadmap.json",
    "/data/mcp-content-roadmap.csv",
    "/data/mcp-security-package.json"
  ]
}