As AI systems become increasingly integrated into software supply chains, enterprise applications, and security infrastructure, the need for structured, secure, and interpretable model interaction layers is paramount. The Model Context Protocol (MCP) is emerging as a framework to define the operational, contextual, and behavioral boundaries of AI models. However, with the power and flexibility of MCPs comes a new class of vulnerabilities and attack surfaces that remain underexplored. This OWASP Top 10 for MCP outlines the most critical security concerns arising in the lifecycle of MCP-enabled systems—spanning from model misbinding, context spoofing, and prompt-state manipulation to insecure memory references and covert channel abuse. These risks are amplified in scenarios involving agentic AI, model chaining, multi-modal orchestration, and dynamic role assignment. By mapping the top 10 MCP-related vulnerabilities and offering concrete recommendations for secure design, implementation, and auditing practices, this project aims to equip AI developers, ML engineers, and security practitioners with the insights necessary to build context-aware and attack-resilient AI systems. The OWASP MCP Top 10 will serve as a living document, evolving alongside the pace of AI model capability and protocol innovation—anchored in real-world threats, research findings, and industry feedback.
MCP01:2025 - Token Mismanagement & Secret Exposure
MCP02:2025 - Privilege Escalation via Scope Creep
MCP03:2025 - Tool Poisoning
MCP04:2025 - Software Supply Chain Attacks & Dependency Tampering
MCP05:2025 - Command Injection & Execution
MCP06:2025 - Prompt Injection via Contextual Payloads
MCP07:2025 - Insufficient Authentication & Authorization
MCP08:2025 - Lack of Audit and Telemetry
MCP09:2025 - Shadow MCP Servers
MCP10:2025 - Context Injection & Over-Sharing
The most up-to-date OWASP MCP Top 10 is available here: ➡️ https://github.com/OWASP/www-project-mcp-top-10/ We proudly recognize contributors across the following categories: Roles & Recognition Authors Primary writers and core content creators behind major MCP Top 10 sections. Reviewers Community members who regularly provide constructive input through GitHub issues or PR reviews. Top Contributors Contributors who have made significant, high-quality contributions — typically 500+ additions. Contributors Individuals who have added meaningful content — generally 50+ additions. Mini Contributors Supporters who made smaller contributions — less than 50 additions (even a line counts!). Editors Folks helping in refine, format, and improve clarity, structure, and consistency. Note: Our contributor table is generated from GitHub contribution activity. Details on how these numbers are collected can be found in the project README. We refresh the table manually, so if you don’t see your name yet, don’t worry it may appear during the next update cycle! Every contribution matters from a single sentence to full sections — and helps strengthen the MCP Top 10. Thank you for helping the community grow! Name|Twitter|LinkedIn