Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

MCP update removes prompt verification, exposing credentials to theft.

MCPโ€™s latest update shifts prompt verification from agents to servers, removing a critical security check. This change allows attackers to steal credentials by tricking agents into sending data to maโ€ฆ

MCP's new spec turns a planted prompt into a stolen credential
VentureBeat โ€” 5 September 2026
Text:
53 0 0

On Julyโ€ฏ28, the Model Context Protocol (MCP) released its biggest update yet, shifting security responsibilities and exposing a new risk for enterprise tools. The update was rolled out across all four Tierโ€ฏ1 software development kits (SDKs) within a single day, and Cloudflareโ€™s Agents SDK was ready from the start. Companies such as Sentry and Linear immediately adopted the new version, meaning the changes are already live in production.

The new version focuses on scaling and usability. MCP now runs a stateless core that can handle ordinary HTTP traffic, uses OAuthโ€‘native authorization for tighter access control, and supports serverโ€‘rendered user interfaces through MCP Apps. The protocol also introduces a 12โ€‘month deprecation policy that locks in these changes until at least midโ€‘2027, giving developers a clear timeline to migrate.

However, the most significant change is where security enforcement now sits. Earlier versions required the agent software to verify that prompts came from trusted sources before sending any credentials. The new spec moves that verification to the server side, meaning the agent will forward any prompt it receives without checking its origin. This shift turns a simple planted prompt into a potential theft vector: an attacker can trick the agent into sending a userโ€™s credentials to a malicious server, and the agent will comply because it no longer checks the promptโ€™s source. The change was designed to simplify the agentโ€™s logic, but it also removes a key line of defense.

Developers are reacting with caution. Some are already planning patches that reโ€‘enable prompt validation in the agent, while others are monitoring the new specโ€™s adoption in their own deployments. The security community is calling for clearer guidance on how to mitigate the new risk without compromising the protocolโ€™s scalability goals. The next step will be to evaluate how many customers rely on the agent in sensitive contexts and to roll out updates that restore the missing checks. This shift highlights the tradeโ€‘off between performance and security, and it will be a focal point for future MCP revisions.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

5 Android phones you should buy instead of the Samsung Galaโ€ฆ
๐Ÿ’ป Technology
5 Android phones you should buy instead of the Samsung Galaxy S26 FE
Android Authority ยท 8 days ago
5 Android phones you should buy instead of the Fairphone Geโ€ฆ
๐Ÿ’ป Technology
5 Android phones you should buy instead of the Fairphone Gen 6 Plus
Android Authority ยท 14 days ago
HTC Vive Eagle smart glasses finally come to the west
๐Ÿ’ป Technology
HTC Vive Eagle smart glasses finally come to the west
Engadget ยท 13 days ago
Lori Loughlin files for divorce from Mossimo Giannulli afteโ€ฆ
๐ŸŒ World News
Lori Loughlin files for divorce from Mossimo Giannulli after nearly 30 years
NBC News ยท 8 days ago
U.S. cartoonists illustrate political controversies throughโ€ฆ
๐Ÿ›๏ธ Politics
U.S. cartoonists illustrate political controversies through satire and humor
Politico ยท 12 days ago
Is SK Hynix a Millionaire-Maker Stock?
๐Ÿ“ˆ Markets & Finance
Is SK Hynix a Millionaire-Maker Stock?
Nasdaq News ยท 15 days ago
Full view