#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
About this talk
This talk by Simcha Kosman addresses the vulnerabilities of MCP servers, emphasizing that static prompt-sanitizing is an outdated defense mechanism. The speaker revisits the Tool-Poisoning Attack and critiques the effectiveness of monitoring description fields. By leveraging fuzzing techniques on auto-generated JSON schemas, the session introduces Full-Schema Poisoning, which exploits various payloads that can manipulate LLM reasoning. Additionally, the speaker presents Advanced Tool-Poisoning Attacks that utilize runtime errors to extract sensitive data while bypassing static analysis. The discussion concludes with the proposal of a zero-trust strategy that includes schema design, allowing listing, and runtime differential auditing, highlighting that these measures are crucial starting points for enhancing security.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Finding Bugs in V8: A Formal Verification Approach by Simon Gerst
36:58