April 2026Unreviewed
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
Yannis Belkhiter, Giulio Zizzo, Sergio Maffeis, Seshu Tirupathi, John D. Kelleher
Abstract
The growth of agentic AI has drawn significant attention to function calling Large Language Models (LLMs), which are designed to extend the capabilities of AI-powered system by invoking external functions. Injection and jailbreaking attacks have been extensively explored to showcase the vulnerabilities of LLMs to user prompt manipulation. The expanded capabilities of agentic models introduce further vulnerabilities via their function calling interface. Recent work in LLM security showed that fun
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0053AI Agent Tool Invocation
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{belkhiter2026breaking,
title = {{Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models}},
author = {Yannis Belkhiter and Giulio Zizzo and Sergio Maffeis and Seshu Tirupathi and John D. Kelleher},
year = {2026},
month = apr,
eprint = {2604.20994},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.20994}
}