Observations
Known vulnerabilities in MCP server packages
Our mirror of the official MCP Registry holds 38,189 servers (the latest version of each; 454 marked deprecated by the registry). 13,996 of them publish only packages whose exact version could be looked up in OSV.dev; 5 of those have at least one known vulnerability on file. Checks shown here ran between 2026-10-01 and 2026-10-01.
Not checkable means unknown, not safe. These servers are remote-only, ship as container images or bundles, or publish no exact package version, so OSV.dev cannot be asked about them. They carry no count at all.
Registry namespaces: 25,114 published under a GitHub-account namespace, 13,075 under a domain namespace. The registry checks ownership of the namespace at publish time; that says who published, not whether the code is safe.
Servers with known vulnerabilities
Counts apply to the package version the registry lists, which may be older than the project's current release. They do not weigh severity or whether a flaw is reachable through the MCP server. Each advisory links to its OSV.dev record.
How we measure
- We mirror the latest version of every server in the official MCP Registry.
- For each server whose packages are all on npm, PyPI, NuGet or crates.io (ecosystems OSV.dev covers) with an exact version, we ask OSV.dev (querybatch) which known vulnerabilities affect each package at that exact version. If any package of a server cannot be looked up, the whole server is marked not checkable: a partial count would understate it.
- Advisory ids that are aliases of the same flaw (GHSA, PYSEC, CVE) are merged, so one flaw counts once.
- A scheduled job aims to re-ask OSV.dev about each server every 7 days, and sooner when the registry entry changes. The page shows the dates of the oldest and the newest check, and the date each listed server was checked.
- The registry checks who may publish each name at publish time: a GitHub account for io.github.* names, a domain for the rest. That says who published, not whether the code is safe.
Limits
- Only the version the registry lists is checked. It can lag behind the newest release in the package registry.
- Coverage is whatever OSV.dev knows. A vulnerability not yet recorded there is not counted.
- This is not a security audit and does not read the servers' code.
- The absence of a record in OSV.dev is not proof that a server is secure.
- Only the package itself is looked up, not the dependencies it installs.
- For servers that also offer a remote endpoint, only the published package is checked, not the hosted service.
- Remote-only servers, container images (OCI), MCPB bundles and packages without an exact version cannot be checked this way. They have no count: unknown, not safe.
Raw data: /mcp-security/data.json. General rules for everything we publish are in the methodology.
