Trendmicro
AI-Powered Vulnerability Sweep Reveals 15,000 Flaws in MCP Servers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A recent Trendmicro report identified over 15,000 vulnerabilities across 19,000 open-source MCP servers, with a significant portion potentially influenced by AI-generated code. The research utilized a Gemini-powered AI agent to analyze repository metadata and source code traits. Initial scans flagged 17,558 vulnerabilities, later refined to 15,000 after removing false positives. A manual review of 438 selected vulnerabilities confirmed their status. The analysis highlighted a growing trend in AI bot activity on GitHub, with 8.3% of MCP repositories showing such activity. This situation raises concerns about the security and reliability of AI-assisted code development, as the presence of vulnerabilities could impact a wide range of applications relying on these servers.
Key Points: • Over 15,000 vulnerabilities identified in 19,000 MCP servers. • 8.3% of analyzed repositories showed AI bot activity, indicating AI's role in code development. • The research utilized advanced AI tools to assess and refine vulnerability findings.