Unauthenticated attackers can exploit multiple vulnerabilities in the Terraform MCP Server to bypass access control mechanisms, disclose sensitive information, and manipulate data.
A missing prompt injection protection measure in the Azure DevOps MCP server allows hidden comments to redirect control flow of AI agents and trigger data leaks.
Smartsheet operates an MCP server on AWS that provides AI agents with structured access to platform data and has saved 3 billion tokens to date through token optimizations.