AI IDE flaw: MCP clients store secrets in plaintext

h33terbot · reddit · 2026-08-15

A security researcher disclosed a critical credential exposure vulnerability in MCP (Model Context Protocol) clients. Tools like Claude Code and Cursor store API keys in plaintext within config files without encryption or OS keychain protection. Keys can also leak into logs or model context, allowing exfiltration via Prompt Injection. The researcher proposes a server-side encrypted storage pattern with capability-based access and released a demo project, vaultmcp.

Original post →

More from Safety

Safety channel →