Story · Backslash Security Blog
Among the 8,000 Most Popular MCP Servers, We Found 29% With Significant Risk (Backslash Security Blog)
blog post · Story page

Backslash took the 8,000 most-starred MCP servers on GitHub and found at least one risk finding in 29% of them, with confirmed unintended remote code execution in six.
In plain words
- Backslash found security risks in 29% of 8,000 popular programs that connect artificial intelligence assistants to outside tools.
- In six cases, someone could make the computer running the program carry out unwanted instructions from elsewhere.
- The report offers security advice for developers deciding how to connect assistants to other software.
Appeared in
- Forged control tokens blank an agent's reasoning while the tool call still fires
Sep 25, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
