Governance Gaps Identified in MCP Servers
Researchers highlighted risks in Model Context Protocol integrations, including unauthorized file access and lack of geographic data control.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust AI applications to access your company's sensitive data without additional security checks?
Ox Security recently identified systemic governance vulnerabilities within Model Context Protocol (MCP) servers, which facilitate connections between AI models and external data. The findings reveal potential risks regarding geographic data sovereignty and persistent authorization.
Why it matters
The lack of protocol-level geographic controls and systemic authorization flaws in MCP architecture could allow AI applications to inadvertently leak sensitive information to non-local servers. These findings highlight the security challenges inherent in standardized protocols that automate AI access to local environments.
Analysis of 5,095 unique hostnames found 16% resolving outside the U.S. in regions including Russia and China. Tests demonstrated that Claude Code, when granted always-allow permissions, can retrieve sensitive .env files through these MCP connections.
The players
Ox Security
A cybersecurity research firm focused on identifying systemic vulnerabilities in AI integration protocols and development stacks.
Model Context Protocol
An open-standard protocol designed to connect AI applications to external tools and data sources.
The details
MCP uses a standardized interface to connect AI agents to local tools and files. The vulnerability stems from how these applications handle 'always-allow' permissions, which grant an MCP server ongoing access to local resources without subsequent user confirmation. Furthermore, because the protocol lacks a built-in regional designation for servers, traffic may be routed to international infrastructure without administrative oversight or compliance with local data residency requirements.
Timeline
June 2025: A report identified the NeighborJack vulnerability affecting hundreds of MCP servers.
April 2026: Researchers reported a vulnerability involving arbitrary command execution in MCP.
September 2026: Ox Security published a report on current MCP governance gaps.
The Tech Race
This analysis marks a shift in the security research landscape surrounding the Model Context Protocol, moving from identifying isolated bugs to auditing systemic governance. It follows a series of reports since 2025 regarding arbitrary code execution risks that threaten to undermine the protocol's adoption.
Users currently deploying MCP servers should review their always-allow permission settings to prevent unauthorized access to local sensitive files. Developers must verify the geographic residency of their selected MCP hosts until the protocol implements native regional controls.
The takeaway
The transition of AI agents from local scripts to interconnected, protocol-driven architecture is outpacing current security governance standards. Users should monitor the protocol's official updates for the potential implementation of geographic routing controls and more granular permission gating.
Further reading
For broader trends in AI infrastructure defense, explore the latest research at Cybersecurity.
Source note: This article includes information reported by Infosecurity Magazine.
Live Poll
Do you trust AI applications to access your company's sensitive data without additional security checks?







