
GhostSplice: Malicious MCP Servers Exploit AI Coding Agents to Exfiltrate Secrets
AI_securityprompt_injectiondata_exfiltrationvulnerabilitycybersecurity
The ASSET Research Group disclosed a vulnerability called GhostSplice, where malicious MCP (Multi-Component Prompt) servers manipulate AI coding agents. These servers split instructions into fragments to bypass security controls and induce agents to exfiltrate sensitive data. The attack exploits the way AI agents process and reassemble segmented prompts. The findings are detailed in the group’s disclosure report.