Governance Gaps Identified in MCP Servers

New research from Ox Security reveals systemic vulnerabilities and geographic risks within Model Context Protocol servers.

Updated on Sept. 28, 2026 in Cybersecurity

Isometric editorial illustration of a heavy-duty server rack, rendered in muted teal, cream, and deep red, representing technical infrastructure security.
Ox Security research has identified systemic security vulnerabilities within Model Context Protocol servers, noting risks related to arbitrary command execution and insufficient geographic governance. AI Illustration. Upload story photo >

Live Poll

Do you trust AI applications to access your company's sensitive data without additional security checks?

Ox Security recently published a report detailing significant governance vulnerabilities within Model Context Protocol (MCP) servers. The study highlights security risks arising from standardized protocols that lack geographic region controls.

Why it matters

MCP allows AI applications to access external tools and data, but the current architectural design permits systemic vulnerabilities that can expose sensitive files. Users who grant always-allow permissions risk unauthorized access because the protocol lacks a native concept of geographic boundaries.

The analysis of 5,095 unique hostnames found that 16% resolve to locations outside the United States, including Russia and China. Additionally, 2% of the hostnames identified in the report are no longer active.

The players

Ox Security

This is a cybersecurity firm that specializes in identifying and mitigating risks within software supply chains and AI-integrated protocols.

Model Context Protocol

This is an open standard designed to facilitate connections between AI applications and external data sources or tools.

The details

Researchers demonstrated that using Claude Code with always-allow permissions granted unauthorized access to sensitive .env files. The study suggests that MCP servers are susceptible to arbitrary command execution due to existing SDK architectural designs.

Timeline

  1. A Backslash Security report identified the NeighborJack vulnerability in June 2025.

  2. Ox Security released a report on arbitrary command execution vulnerabilities in April 2026.

  3. Ox Security published their current report on MCP governance gaps in September 2026.

The Tech Race

The research follows the pattern set by the 2025 NeighborJack vulnerability, indicating that systemic security issues in MCP remain an ongoing concern. These findings highlight the difficulty of securing decentralized AI-integrated protocols against arbitrary command execution risks.

Users currently leveraging AI applications that connect to MCP servers should review their permission settings to disable always-allow access. Failure to restrict these permissions could result in unauthorized third-party access to sensitive local environment files.

The takeaway

Securing AI-integrated workflows requires a shift toward more granular permission management rather than broad trust models. Users must remain vigilant regarding the external tools their AI models are permitted to access by default.

Further reading

For more information on securing integrated AI frameworks, visit the Cybersecurity section.

Live Poll

Do you trust AI applications to access your company's sensitive data without additional security checks?