Critical · CVSS 9.8 May 12, 2026 · OX Security

MCP Toolchain Vulnerabilities

The Integration Layer Is the Attack Surface

OX Security disclosed critical vulnerabilities across Model Context Protocol server implementations on May 12, 2026. MCP servers bridge AI agents to APIs, local services, files, and operational systems — and that integration layer is now the primary attack surface. Two CVEs affect toolchains with over 140,000 GitHub stars and an ecosystem reaching approximately 150 million downloads. Attackers can achieve remote code execution, API key theft, and lateral movement across clusters and cloud systems.

2 CVEs
9.8 Max CVSS
~150M Downloads Affected
7,000+ Exposed Servers

"The integration layer is not a secondary concern. It is the attack surface."

— OX Security

CVE Details

CVE-2025-65719 Critical · 9.8 Remote Code Execution

kubectl-mcp-server Arbitrary Code Execution via Crafted HTML

kubectl-mcp-server v1.1.1 allows arbitrary code execution via crafted HTML. An attacker can lure a user to a malicious page that bypasses assumed local-only protections, triggering code execution under the victim's credentials through the MCP server's Kubernetes integration surface.

Affected: kubectl-mcp-server v1.1.1  ·  Impact: Arbitrary code execution, potential cluster-level lateral movement via Kubernetes API access.
CVE-2025-69443 Medium · 6.3 Multi-Vector

Archon Remote Code Execution, Prompt Execution, UI Control, and API Key Theft

Archon 0.1.0 contains a vulnerability enabling remote code execution, arbitrary prompt execution, UI control, and API key theft. The MCP server's integration surface allows attackers to invoke MCP functions under victim credentials, extract sensitive API keys, and leverage access for lateral movement.

Affected: Archon 0.1.0  ·  Impact: RCE, prompt execution, UI control, API key exfiltration, lateral movement across cloud systems.

Attack Path

1

Lure to Malicious Page

Attacker lures the victim to a crafted HTML page — via phishing, a compromised link, or a malicious web resource. The page contains exploit code targeting the locally running MCP server.

MCP servers running locally are not isolated from browser-accessible resources. Treat local MCP exposure the same as any network-accessible service.

2

Bypass Local-Only Protections

The exploit bypasses assumed local-only protections — such as the belief that localhost-bound services are inaccessible from the web. Without origin validation or authentication, the MCP server accepts requests from the malicious page.

Bind MCP services to loopback and enforce strict origin validation. "Local only" is not a security boundary without explicit controls.

3

Invoke MCP Functions Under Victim Credentials

With access to the MCP server, the attacker invokes tool functions using the victim's existing credentials and permissions — Kubernetes API access, file system operations, cloud API calls.

Require explicit authentication for all MCP function invocations. Ambient credential access is an implicit privilege escalation path.

4

Extract API Keys and Sensitive Data

MCP servers with access to configuration files, environment variables, or secret stores expose that material through their tool interfaces. API keys, tokens, and credentials are exfiltrated to attacker-controlled infrastructure.

Audit exactly what secrets and credentials each MCP server can access. Apply least privilege — connectors should not inherit developer-session credentials.

5

Lateral Movement Across Clusters and Cloud Systems

Stolen credentials and API access enable lateral movement — across Kubernetes clusters, cloud accounts, SaaS integrations, and any other system reachable through the MCP server's toolchain.

MCP servers with Kubernetes or cloud API access can become a pivot point for cluster-wide compromise. Scope permissions to the minimum required for the specific workflow.

Scale of Impact

Directly Affected

  • kubectl-mcp-server v1.1.1
  • Archon 0.1.0
  • 140,000+ combined GitHub stars
  • 60,000+ DockerHub downloads

Broader Ecosystem

  • 7,000+ publicly accessible MCP servers
  • ~150 million total downloads
  • Unsafe defaults across MCP ecosystem
  • No authentication by default

Attack Capabilities

  • Remote code execution
  • API key and credential theft
  • Prompt injection and UI control
  • Kubernetes cluster lateral movement

Response Checklist

STEP 01 Inventory All MCP Servers in Your Environment Immediate

Search developer workstations, CI/CD pipelines, cloud workloads, Kubernetes clusters, and container registries for MCP server deployments. Include experimental and developer-local instances — they carry the same risk as production.

STEP 02 Verify kubectl-mcp-server Versions and Patch Immediate

Identify all instances of kubectl-mcp-server v1.1.1 and apply the patched version. Given CVSS 9.8 and the RCE via crafted HTML vector, treat this as a same-day emergency patch.

STEP 03 Bind MCP Services to Loopback Only Urgent

Ensure all MCP servers bind exclusively to 127.0.0.1, not 0.0.0.0. Confirm with netstat or ss -tlnp — binding address is not always visible in config files.

STEP 04 Enforce Origin Validation on All MCP Endpoints Urgent

MCP servers must validate the Origin header on all incoming requests. Requests from unexpected origins — including browser-originated cross-site requests — should be rejected with a 403. This is the primary control against the crafted-HTML attack vector.

STEP 05 Require Authentication for All MCP Function Invocations Urgent

No MCP function should be callable without explicit authentication. Ambient credential access — where the server inherits the developer's session — is an implicit privilege escalation path that removes all access boundaries.

STEP 06 Audit MCP Server Credential Access Urgent

Document exactly which secrets, API keys, environment variables, and cloud credentials each MCP server can access. Remove access to anything not required for the specific tool workflow. MCP connectors should not inherit developer-session credentials or production secrets.

STEP 07 Define Formal MCP Connector Security Standards Important

Establish organization-wide standards for MCP connector deployment: least-privilege access, scoped credentials with expiry, audit logging of all tool invocations, origin validation, and authentication requirements. Apply these to every current and future MCP integration.

Governance Framework

Named Ownership

Every MCP server deployment must have a named owner, a documented purpose, and a defined credential scope. Ownerless connectors are unmanaged attack surfaces.

Least Privilege Access

MCP connectors should not inherit developer-session credentials. Use dedicated service accounts with the minimum permissions required for the specific workflow.

Audit Logging

Log all MCP tool invocations — function name, caller identity, parameters, and outcome. Alert on invocations outside normal usage patterns or from unexpected origins.

Secure-by-Default Templates

New MCP integrations should start from a template that enforces loopback binding, origin validation, authentication, and scoped credentials — not as an afterthought.

Patch Cadence

MCP servers are now first-class targets. Apply the same emergency patch cadence to AI toolchain infrastructure as to internet-facing web services.

Supply Chain Review

Treat MCP plugins and connectors as supply-chain artifacts. Require peer review and ownership tracking before deploying any new MCP integration into a developer or production environment.

References

[1] OX Security

MCP Toolchain Vulnerabilities Disclosure — May 12, 2026

[2] NVD

CVE-2025-65719 — kubectl-mcp-server Arbitrary Code Execution via Crafted HTML

[3] NVD

CVE-2025-69443 — Archon RCE, Prompt Execution, UI Control, and API Key Theft

Primary source: OX Security disclosure, May 12, 2026. This advisory is an independent defensive guide produced by Spectreworks AI for educational purposes only and is not affiliated with OX Security.