New MCP Specification Shifts Security Burden to Developers, Introducing Fresh Risks
The updated Model Context Protocol (MCP) transitions to a stateless, enterprise-ready architecture, but in doing so it offloads critical security responsibilities onto developers and operators rather than enforcing protections at the protocol level. This design shift means that misconfigurations, poor coding practices, and lack of awareness can directly introduce vulnerabilities such as XSS, data leakage via HTTP headers, state tracking identifier misuse, and denial-of-service exposure. The risk is particularly acute because many developers may assume the protocol itself provides safety guarantees it no longer does. As AI-integrated protocols like MCP become foundational enterprise infrastructure, the security posture of every deployment becomes only as strong as the team implementing it.
Tactical Insight
Immediate actions
- Audit all existing MCP implementations for improper state tracking identifier handling and exposed HTTP headers containing sensitive data.
- Establish input validation and output encoding standards for all MCP App integrations to mitigate XSS risks.
Long-term improvements
- Embed secure-by-default configuration templates and developer security guidelines into your MCP deployment pipeline.
- Implement rate limiting and timeout controls on all MCP endpoints to prevent denial-of-service via long-running tasks.
- Require mandatory security training for developers working with AI/ML protocol integrations, covering the new threat surface introduced by MCP's stateless architecture.
Detection measures
- Deploy web application firewall (WAF) rules specifically tuned to MCP traffic patterns to detect header leakage and injection attempts.
- Enable centralised logging and anomaly alerting on MCP service endpoints to identify unusual request volumes or unexpected identifier reuse.