<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A design flaw in the MCP protocol.]]></title><description><![CDATA[<p>A design flaw in the MCP protocol. Whoda thunk. Honestly even back when they were first discussing MCP in 2024 I worried about that. Supply chain is enough of a mess, now this?</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://www.securityweek.com/by-design-flaw-in-mcp-could-enable-widespread-ai-supply-chain-attacks/">
Just a moment...
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://www.securityweek.com/by-design-flaw-in-mcp-could-enable-widespread-ai-supply-chain-attacks/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.securityweek.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.securityweek.com)</span></p>
</a>
</div></p><p><a href="https://infosec.exchange/tags/mcp" rel="tag">#<span>mcp</span></a> <a href="https://infosec.exchange/tags/vulnerability" rel="tag">#<span>vulnerability</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/d9816500-3bd7-4a88-b62c-6f16b9a7d0d2/a-design-flaw-in-the-mcp-protocol.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 04:56:44 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/d9816500-3bd7-4a88-b62c-6f16b9a7d0d2.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 16 Apr 2026 03:46:41 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to A design flaw in the MCP protocol. on Thu, 16 Apr 2026 11:52:49 GMT]]></title><description><![CDATA[<p><span><a href="https://fosstodon.org/@dmikusa">@<span>dmikusa</span></a></span> No, it's nothing new. Once I actually got all the way down to the white paper, I discovered that there really isn't much to this at all, other than: hey, if you have an agent unprotected on your local machine, it can do bad things. That is an important message and should be gotten out there however it gets out there, but certainly not worth all the AI-generated hype and process of the original article.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116414242477944645</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116414242477944645</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 11:52:49 GMT</pubDate></item><item><title><![CDATA[Reply to A design flaw in the MCP protocol. on Thu, 16 Apr 2026 11:43:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> I read that article and it’s got a lot of claims but is lacking in detail, have you seen anything more specific? Wondering if this is something new? Local MCP has always been a mine field, because you’re downloading unsandboxed code and running it on your machine. It’s the exact same problem as most package managers or download installer.exe and double click. It’s all rolling the dice. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3b2.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--game_die" style="height:23px;width:auto;vertical-align:middle" title="🎲" alt="🎲" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3b2.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--game_die" style="height:23px;width:auto;vertical-align:middle" title="🎲" alt="🎲" /></p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/dmikusa/statuses/116414205067398048</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/dmikusa/statuses/116414205067398048</guid><dc:creator><![CDATA[dmikusa@fosstodon.org]]></dc:creator><pubDate>Thu, 16 Apr 2026 11:43:19 GMT</pubDate></item><item><title><![CDATA[Reply to A design flaw in the MCP protocol. on Thu, 16 Apr 2026 09:38:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/joriki%40infosec.exchange">@<span>joriki</span></a></span> The Most Battle Weary Man in the World. "I don't ever drink beer. Scotch. Double. Neat."</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116413713664939896</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116413713664939896</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 09:38:20 GMT</pubDate></item><item><title><![CDATA[Reply to A design flaw in the MCP protocol. on Thu, 16 Apr 2026 05:44:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> </p><p>I don't always lol lmfao, but when I do it's usually about cryptocurrency and AI</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joriki/statuses/116412793131026019</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joriki/statuses/116412793131026019</guid><dc:creator><![CDATA[joriki@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 05:44:14 GMT</pubDate></item></channel></rss>