This article examines five critical and high-severity security vulnerabilities affecting MCP servers, grounded in OWASP’s agentic AI guidelines. The piece identifies unauthenticated tool access, prompt injection via tool results, excessive agent permissions, persistent token exposure, and missing audit trails as the primary threats, then provides concrete mitigation strategies for each vulnerability.