Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Insecure credential storage plagues MCP

Summary

This post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
Published
Collected

original ↗

Related coverage

back