Topic · DiggingBeagle record

MCP control-plane exposure

An MCP endpoint exposes privileged local or remote capabilities without adequate authentication, origin checks or action constraints.

Topic kind
pattern

Definition & limits

MCP can connect models to powerful tools. When transport-level trust is weak, ordinary web or network inputs can become a path to commands, files or host processes.

Examples

  • MCP Inspector proxy requests launching stdio commands.
  • Windows-MCP HTTP transport exposing PowerShell.

Research using this topic (5)

Cite this record

DiggingBeagle. “MCP control-plane exposure.” https://diggingbeagle.com/concepts/mcp-control-plane-exposure/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.