A new vulnerability, CVE-2025-54136, dubbed "MCP Tool Schema Poisoning," allows attackers to silently alter the functionality of AI tools by manipulating their JSON schema definitions. This attack bypasses traditional content filters because the schema mutation occurs at a structural level, not within the prompt text. Once a tool's schema is approved, subsequent changes can grant malicious capabilities like unauthorized file access or network calls, as demonstrated by the MCPoison vulnerability which achieved a 36.5% success rate across various LLMs. AI
IMPACT Highlights a critical security gap in AI agent frameworks, necessitating new validation mechanisms beyond prompt-level filtering.
RANK_REASON Disclosure of a novel vulnerability and associated benchmark testing in AI tool interaction. [lever_c_demoted from research: ic=1 ai=1.0]
- Anthropic
- Claude-3.7-Sonnet
- Cursor
- CVE-2025-54136
- Gemini 1.5 Pro
- GPT-4o
- json-schema
- MCP
- MCPoison
- OpenAI
- o1-mini
- OWASP MCP03:2025
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →