Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

MCP update removes prompt verification, exposing credentials to theft.

MCPโ€™s latest update shifts prompt verification from agents to servers, removing a critical security check. This change allows attackers to steal credentials by tricking agents into sending data to maโ€ฆ

MCP's new spec turns a planted prompt into a stolen credential
VentureBeat โ€” 5 September 2026
Text:
40 0 0

On Julyโ€ฏ28, the Model Context Protocol (MCP) released its biggest update yet, shifting security responsibilities and exposing a new risk for enterprise tools. The update was rolled out across all four Tierโ€ฏ1 software development kits (SDKs) within a single day, and Cloudflareโ€™s Agents SDK was ready from the start. Companies such as Sentry and Linear immediately adopted the new version, meaning the changes are already live in production.

The new version focuses on scaling and usability. MCP now runs a stateless core that can handle ordinary HTTP traffic, uses OAuthโ€‘native authorization for tighter access control, and supports serverโ€‘rendered user interfaces through MCP Apps. The protocol also introduces a 12โ€‘month deprecation policy that locks in these changes until at least midโ€‘2027, giving developers a clear timeline to migrate.

However, the most significant change is where security enforcement now sits. Earlier versions required the agent software to verify that prompts came from trusted sources before sending any credentials. The new spec moves that verification to the server side, meaning the agent will forward any prompt it receives without checking its origin. This shift turns a simple planted prompt into a potential theft vector: an attacker can trick the agent into sending a userโ€™s credentials to a malicious server, and the agent will comply because it no longer checks the promptโ€™s source. The change was designed to simplify the agentโ€™s logic, but it also removes a key line of defense.

Developers are reacting with caution. Some are already planning patches that reโ€‘enable prompt validation in the agent, while others are monitoring the new specโ€™s adoption in their own deployments. The security community is calling for clearer guidance on how to mitigate the new risk without compromising the protocolโ€™s scalability goals. The next step will be to evaluate how many customers rely on the agent in sensitive contexts and to roll out updates that restore the missing checks. This shift highlights the tradeโ€‘off between performance and security, and it will be a focal point for future MCP revisions.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

How to watch the 2026 US Open Tennis Championships
๐Ÿ’ป Technology
How to watch the 2026 US Open Tennis Championships
Engadget ยท 13 days ago
5 Android phones you should buy instead of the Fairphone Geโ€ฆ
๐Ÿ’ป Technology
5 Android phones you should buy instead of the Fairphone Gen 6 Plus
Android Authority ยท 10 days ago
Google Maps has changed Lake Ontario to Lake America for USโ€ฆ
๐Ÿ’ป Technology
Google Maps has changed Lake Ontario to Lake America for US users
Engadget ยท 13 days ago
Lori Loughlin files for divorce from Mossimo Giannulli afteโ€ฆ
๐ŸŒ World News
Lori Loughlin files for divorce from Mossimo Giannulli after nearly 30 years
NBC News ยท 3 days ago
Nepal warns of more flooding as China assesses Tibet storm โ€ฆ
๐ŸŒฑ Environment
Nepal warns of more flooding as China assesses Tibet storm damage
NBC News ยท 12 days ago
WhatsApp chat used to send cash for crime and extremism
๐ŸŒ World News
WhatsApp chat used to send cash for crime and extremism
BBC World News ยท 13 days ago
Full view