Versatile AI Risk Assessment

AI threat catalogueApplication and Integration SecurityProduction

MCP Hijacking (Model Context Protocol)

The Model Context Protocol (MCP) connects AI assistants to external tools and data sources in a standardised way. Attackers hijack MCP servers or manipulate their tool descriptions and thereby control what the AI system sees and does.

As of: July 2026 · Catalogue version 2026.07.17.3 · 6 mitigations · 14 verified sources

Description

MCP servers provide tools to an AI system and describe them in manifests (description files) the system trusts. Attackers strike at several points: they operate or take over an MCP server, distribute initially harmless servers and later ship a malicious update, poison tool descriptions with hidden instructions, or insert themselves into unprotected connections (man-in-the-middle, reading and altering the traffic). The manipulated content reaches the model as seemingly trustworthy context and undermines the trust boundary between application and model. Thousands of freely available MCP servers circulate without consistent security vetting.

Possible impact

Attackers read everything that flows through the assistant, including emails, documents and credentials, trigger commands within the assistant's permissions or silently redirect results. Because everything runs through legitimate tool calls, the attack is hard to notice in operation. The risks include data leakage with GDPR consequences, manipulated work results and loss of control over connected systems.

Example

A team connects a freely available MCP server for sending emails to its AI assistant. After several unremarkable versions, the provider ships an update that forwards every sent email as a blind copy to the attacker.

Recommended mitigations (6)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 ASI01:2026 · ASI02:2026 · ASI04:2026 · LLM01:2025 · LLM06:2025NIST AI RMF Section 3.5 · NISTAML.015 · NISTAML.039MITRE ATLAS AML.T0048 · AML.T0051 · AML.T0053EU AI Act Article 14(4)(d) · Article 9(1), 9(2)(a), 9(2)(d)BSI R28

Verified references (14)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Application and Integration Security.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“MCP Hijacking (Model Context Protocol)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/mcp-hijacking/

← Back to the full catalogue