Skip to content
CBContext/Bleed Wiki
← Evidence library
Technical report

Guidance · 2025

Context Injection & Over-Sharing

OWASP MCP Top 10

What it says

Security guidance for contexts that are shared, retained or insufficiently scoped across users, agents and workflows.

Why it matters here

One of the clearest current uses of ‘session bleed’ within applied guidance for multi-tenant agentic systems.

Editorial caution

This is applied guidance or a technical synthesis rather than a controlled academic finding.

MCPcross-userisolation
Open original source