About this talk
This talk, titled MCPwned, explores a significant yet often ignored weakness in MCP specifications, specifically focusing on browser-based DNS rebinding. Jonathan Leitschuh demonstrates how this vulnerability can be exploited to compromise SSE and streaming-HTTP MCP servers, allowing attackers to exfiltrate sensitive data and escalate their access. The session reveals how simply visiting a malicious website can lead to the hacking of a locally running MCP server, highlighting the implications of this skeleton key vulnerability.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30