1. EachPod
EachPod

Episode 283 - Intentionally-Vulnerable MCP Server, Hallucinating Software Packages

Author
Ken Johnson and Seth Law
Published
Tue 22 Apr 2025
Episode Link
https://absolute-appsec-eps.s3.us-west-1.amazonaws.com/episodes/Absolute_AppSec_Ep_283.mp3

Ok, so vulnerable MCP tools are a thing now? Ken demonstrates installing and running an intentionally vulnerable MCP server with a bunch of example issues. Following is a discussion of the recent article and research around hallucinations of 3rd party dependencies/libraries in AI-Generated Python and JavaScript. New attack targets all dependent on how creative the LLM is allowed to be. A short aside on why we talk about AI and LLMs so much.

Share to: