Security researcher Syed Anas Mohiuddin identified attacks that use trust gaps in Model Context Protocol (MCP), a standard for communication between AI applications and agents on internal networks. The technique can make one agent pass a malicious instruction to another, leading to actions such as database exfiltration and the disclosure of sensitive business or personal information. Special-purpose agents, including translation and data-analysis systems, may apply weaker safeguards than the underlying language model.
Over the five months before October 5, 2026, Google and four other organizations acknowledged vulnerabilities involving this pattern. Mohiuddin tested agents associated with Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. MCP servers store credentials for individual agents, and internal agents commonly trust one another. Carefully crafted prompts can therefore cause server-side request forgery, making a server send unauthorized network requests.
Rapid7’s CVE-2026-97228 received a severity score of 2.7 and was fixed the previous month. Google’s issue received a score of 8. Its googleapis/mcp-toolbox database MCP tool created an HTTP client without a CheckRedirect policy and did not validate destination IP addresses. A crafted path parameter could redirect a request to an internal endpoint. Google’s remediation added IP-range allow-lists and block lists, and rejects unsafe base URLs during startup.
Mohiuddin calls the broader pattern protocol pivoting. An attacker enters through MCP, exploits trust between communication systems, and reaches capabilities exposed through another protocol, such as Google’s Agent-to-Agent (A2A) system or the emerging Agent Network Protocol. X41 D-Sec researcher Markus Vervier classifies the technique as indirect prompt injection and says the protocol change is not required for the attack.
The attacks succeeded across five organizations that shared MCP use as their notable common factor. Security specialists say rapid adoption has outpaced testing and has weakened zero-trust practices. Sensitive transactions between agents should require authorization, and content passed from a language model to a tool should be handled as untrusted input. The underlying weaknesses remain familiar injection and SSRF flaws.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.