Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

MCP update removes prompt verification, exposing credentials to theft.

MCPโ€™s latest update shifts prompt verification from agents to servers, removing a critical security check. This change allows attackers to steal credentials by tricking agents into sending data to maโ€ฆ

MCP's new spec turns a planted prompt into a stolen credential
VentureBeat โ€” 5 September 2026
Text:
4 0 0

On Julyโ€ฏ28, the Model Context Protocol (MCP) released its biggest update yet, shifting security responsibilities and exposing a new risk for enterprise tools. The update was rolled out across all four Tierโ€ฏ1 software development kits (SDKs) within a single day, and Cloudflareโ€™s Agents SDK was ready from the start. Companies such as Sentry and Linear immediately adopted the new version, meaning the changes are already live in production.

The new version focuses on scaling and usability. MCP now runs a stateless core that can handle ordinary HTTP traffic, uses OAuthโ€‘native authorization for tighter access control, and supports serverโ€‘rendered user interfaces through MCP Apps. The protocol also introduces a 12โ€‘month deprecation policy that locks in these changes until at least midโ€‘2027, giving developers a clear timeline to migrate.

However, the most significant change is where security enforcement now sits. Earlier versions required the agent software to verify that prompts came from trusted sources before sending any credentials. The new spec moves that verification to the server side, meaning the agent will forward any prompt it receives without checking its origin. This shift turns a simple planted prompt into a potential theft vector: an attacker can trick the agent into sending a userโ€™s credentials to a malicious server, and the agent will comply because it no longer checks the promptโ€™s source. The change was designed to simplify the agentโ€™s logic, but it also removes a key line of defense.

Developers are reacting with caution. Some are already planning patches that reโ€‘enable prompt validation in the agent, while others are monitoring the new specโ€™s adoption in their own deployments. The security community is calling for clearer guidance on how to mitigate the new risk without compromising the protocolโ€™s scalability goals. The next step will be to evaluate how many customers rely on the agent in sensitive contexts and to roll out updates that restore the missing checks. This shift highlights the tradeโ€‘off between performance and security, and it will be a focal point for future MCP revisions.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Japan's Financial Services Agency plans blockchain system fโ€ฆ
๐Ÿ’ป Technology
Japan's Financial Services Agency plans blockchain system for faster securities settlemenโ€ฆ
CoinTelegraph ยท 10 days ago
Tech Life
๐Ÿ’ป Technology
Tech Life
BBC Technology ยท 11 days ago
Lenovoโ€™s first Android handheld lets you stream PC games wiโ€ฆ
๐Ÿ’ป Technology
Lenovoโ€™s first Android handheld lets you stream PC games without a network connection
Android Authority ยท 11 days ago
Nigeria's jet fuel conundrum: Scarcity at home, abundance aโ€ฆ
๐ŸŒ World News
Nigeria's jet fuel conundrum: Scarcity at home, abundance abroad
DW World ยท 11 days ago
Firms scramble for battery power in Spain and Portugal
๐Ÿ’ฐ Business
Firms scramble for battery power in Spain and Portugal
BBC Business ยท 11 days ago
Is Sudanโ€™s battlefield shaping the terms of its next politiโ€ฆ
๐ŸŒ World News
Is Sudanโ€™s battlefield shaping the terms of its next political phase?
Al Jazeera ยท 11 days ago
Full view