Story · Backslash Security Blog

Among the 8,000 Most Popular MCP Servers, We Found 29% With Significant Risk (Backslash Security Blog)

blog post · Story page

A grid of identical small server crates seen straight on. Roughly a third carry a small tag hanging from one corner. Six crates sit open on a low bench in front of the wall, with a single cable running out of them toward the right.

Backslash took the 8,000 most-starred MCP servers on GitHub and found at least one risk finding in 29% of them, with confirmed unintended remote code execution in six.

In plain words

  • Backslash found security risks in 29% of 8,000 popular programs that connect artificial intelligence assistants to outside tools.
  • In six cases, someone could make the computer running the program carry out unwanted instructions from elsewhere.
  • The report offers security advice for developers deciding how to connect assistants to other software.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.