{"guid":"591309e4-b4c7-4ecc-9667-efe5d34c8f2c","title":"MCP security hot potato: how to stay secure integrating external tools to your LLM","subtitle":null,"slug":"god2025-56487-mcp-security-hot-potato-ho","link":"https://c3voc.de","description":"Model Context Protocol (MCP) is the latest hot topic in cybersecurity. Business wants it (AI is the new mantra), developers are excited (new toys, new code), and security teams are left to make it safe—often with already packed schedules. Let's treat it like just another Tuesday. Like many shiny new technologies (remember the early days of cloud?), MCP is being built with a “features first, security later” mindset. As a fresh piece of tech, it blends novel vulnerabilities with familiar, well-known ones. If you're an early adopter, it's important to accept that MCP and its current implementations are imperfect—and to be ready for that. In this talk, we'll dive into the real-world challenges companies are facing with MCP and equip you with practical remediations.\n We'll cover topics such as:\n                            \nAn introduction to the MCP protocol and its security considerations, including authentication\nEmerging vulnerabilities like prompt injections, tool poisoning, rug pull attacks, and cross-server tool shadowing\nClassic vulnerabilities that may resurface around MCP, based on recent CVEs\nRemediation strategies and available tooling\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Mateusz Olejarka","Dawid Nastaj"],"tags":["56487","2025","god2025","Track 2","god2025-eng","god2025","Day 1"],"view_count":206,"promoted":false,"date":"2025-11-26T14:30:00.000+01:00","release_date":"2025-11-26T00:00:00.000+01:00","updated_at":"2026-04-03T17:15:04.875+02:00","length":1478,"duration":1478,"thumb_url":"https://static.media.ccc.de/media/events/god/2025/56487-591309e4-b4c7-4ecc-9667-efe5d34c8f2c.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2025/56487-591309e4-b4c7-4ecc-9667-efe5d34c8f2c_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2025/56487-591309e4-b4c7-4ecc-9667-efe5d34c8f2c.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2025/56487-591309e4-b4c7-4ecc-9667-efe5d34c8f2c.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2025-56487-mcp-security-hot-potato-ho","url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_title":"German OWASP Day 2025","conference_url":"https://api.media.ccc.de/public/conferences/god2025","related":[],"recordings":[{"size":15,"length":1478,"mime_type":"audio/opus","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2025-11-26T16:12:50.314+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/opus/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_opus.opus","url":"https://api.media.ccc.de/public/recordings/93593","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"},{"size":58,"length":1478,"mime_type":"video/webm","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-11-26T16:26:22.072+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/webm-sd/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/93600","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"},{"size":55,"length":1478,"mime_type":"video/mp4","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-11-26T16:21:33.712+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/h264-sd/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_sd.mp4","url":"https://api.media.ccc.de/public/recordings/93597","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"},{"size":152,"length":1478,"mime_type":"video/webm","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-11-26T16:20:26.095+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/webm-hd/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/93596","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"},{"size":22,"length":1478,"mime_type":"audio/mpeg","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2025-11-26T16:13:21.245+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/mp3/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/93594","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"},{"size":182,"length":1478,"mime_type":"video/mp4","language":"eng","filename":"god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-11-26T15:55:12.874+01:00","recording_url":"https://cdn.media.ccc.de/events/god/2025/h264-hd/god2025-56487-eng-MCP_security_hot_potato_how_to_stay_secure_integrating_external_tools_to_your_LLM_hd.mp4","url":"https://api.media.ccc.de/public/recordings/93580","event_url":"https://api.media.ccc.de/public/events/591309e4-b4c7-4ecc-9667-efe5d34c8f2c","conference_url":"https://api.media.ccc.de/public/conferences/god2025"}]}