Categories: Cyber Security News

Critical MCP Server Vulnerability Exposes 3,000+ Servers and Sensitive API Keys

Security researchers at GitGuardian have uncovered a critical path traversal vulnerability in Smithery.ai, a popular Model Context Protocol (MCP) server hosting platform, that exposed over 3,000 hosted AI servers and compromised thousands of API keys.

The discovery, disclosed by security researcher Gaetan Ferry, highlights growing concerns about centralized AI infrastructure security and supply chain risks.

Docker Build Flaw Opens Door to Mass Compromise

The vulnerability stemmed from a configuration bug in Smithery’s server build process.

The platform, which hosts remote MCP servers to simplify deployment, relies on GitHub repositories containing server code and Docker configurations.

Researchers discovered that the dockerBuildPath parameter was improperly validated, allowing attackers to specify arbitrary filesystem locations as the Docker build context.

By exploiting this path traversal flaw, attackers could access sensitive files on Smithery’s build infrastructure.

Ferry demonstrated the attack by creating a malicious smithery.yaml configuration that pointed the build context to the parent directory, exposing the build user’s home directory.

Using a specially crafted Dockerfile, researchers exfiltrated filesystem listings and discovered Docker authentication credentials stored in the .docker/config.json file.

The compromised credentials proved severely overprivileged, granting access not only to Smithery’s Docker registry but also to fly.io’s machines API.

This allowed attackers to execute arbitrary code on any of the 3,000+ hosted MCP servers and access portions of Smithery’s infrastructure.

Testing revealed that attackers could dump network traffic from compromised servers, capturing API keys and authentication tokens transmitted by thousands of clients.

The vulnerability represents a textbook supply chain attack scenario, where compromising a single trusted platform could cascade into breaches affecting hundreds of organizations.

MCP servers function as gateways to sensitive external services, including databases, APIs, and data sources, making them high-value targets.

The centralized hosting model amplified the potential impact, creating a single point of failure for the entire ecosystem.

Ferry noted that most MCP servers use static, long-term API keys rather than OAuth tokens, which increases exploitation timeframes and limits privilege management capabilities.

This mirrors recent attacks like the Salesloft supply chain compromise, where attackers leveraged stored OAuth credentials to breach multiple customer environments.

GitGuardian disclosed the vulnerability to Smithery on June 13, 2025, and the platform responded swiftly. Within 24 hours, Smithery deployed a partial fix and rotated compromised credentials.

A complete remediation was implemented by June 15, just two days after disclosure. Investigators found no evidence that malicious actors exploited the vulnerability before it was patched.

The incident underscores the critical importance of secure configuration management in AI infrastructure and highlights emerging threats in the rapidly evolving AI security landscape.

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

The post Critical MCP Server Vulnerability Exposes 3,000+ Servers and Sensitive API Keys appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Kevin Feige on Casting Robert Downey Jr. as Doctor Doom: ‘It’s Our Universe’

Marvel Studios mastermind Kevin Feige has opened up about the decision to bring Robert Downey…

28 minutes ago

Project Hail Mary Author Andy Weir Reveals the One Scene From the Book He Wishes Had Made It Into the Movie

Project Hail Mary author Andy Weir has revealed his “only regret” about the movie, confirming…

29 minutes ago

Slay the Spire 2 Roadmap Has No Release Dates So Dev Can Avoid ‘Sloppy Spire 2’

Slay the Spire 2 developer Mega Crit has published a detailed roadmap for Slay the…

2 hours ago

The Best Deals Today: Sony 4K OLED BRAVIA 8 TV, 4K Blu-ray Bundles, AirPods Pro 3, and More

A new weekend has arrived, and today, you can save big on the 4K Movies,…

3 hours ago

Resident Evil Requiem Mercenaries Rumors Heat Up After Alleged Leak

Resident Evil Requiem fans believe next month’s mysterious content update will add a new version…

4 hours ago

Wrestlemania 42: All of the Match Winners, Returns, and Surprises — Updating Live!

Wrestlemania 42 is finally here, and I’m here in Las Vegas at Allegiant Stadium to…

4 hours ago

This website uses cookies.