Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
Function hijacking attacks against MCP-style agentic AI can redirect tool calls and escalate privileges, exposing a new attack surface that conventional prompt-injection defences do not cover.
Summary written by editorial AI · Source link below
arXiv:2604.20994v2 Announce Type: replace Abstract: The growth of agentic AI has drawn significant attention to function calling Large Language Models (LLMs), which are designed to extend the capabilities of AI-powered system by invoking external functions. Injection and jailbreaking attacks have been extensively explored to showcase the vulnerabilities of LLMs to user prompt manipulation. The expanded capabilities of agentic models introduce further vulnerabilities via their function calling i
Editorial Analysis
As enterprises connect LLM agents to business-critical tools, function hijacking creates a privilege-escalation path that bypasses traditional input-validation defences.
Implement strict tool-call allow-lists, sandboxed execution, and output validation for all agentic AI systems before production deployment.
AI agents that call external tools face a new hijacking risk — enterprises need allow-listing and sandboxing controls before deploying agentic systems.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d