Independent researcher Syed Anas Mohiuddin exposed a structural flaw in Model Context Protocol affecting Google, JPMorgan Chase, Weaviate, Rapid7, and multiple governments. The server-side request forgery vulnerability enables attackers to exploit AI agents and exfiltrate sensitive data. Five US federal servers remain unpatched.

News article

Critical MCP Flaw Exposes Widespread AI Agent Security Gaps

A structural flaw in Model Context Protocol has emerged across major organizations, revealing how quickly AI agent security vulnerabilities can spread when foundational standards lack proper hardening. Independent researcher Syed Anas Mohiuddin discovered identical security weaknesses in AI systems operated by Google, JPMorgan Chase, Weaviate, Rapid7, France's interministerial digital directorate (DINUM), and Indonesia's Tangerang city government.

1

2

The vulnerability in AI agents stems from server-side request forgery, where MCP servers accept URLs or endpoints from agents without validating where those addresses actually resolve. This allows attackers to manipulate agents into making unauthorized requests to internal systems, potentially leading to data exfiltration of database contents and sensitive business information. What makes this MCP flaw particularly concerning is that these organizations share no common code or ownership, yet all independently produced the same security gap.

How Protocol Pivoting Exploits Trust Between AI Agents

Mohiuddin calls this attack class "protocol pivoting" because exploits work when an application uses Model Context Protocol to assign tasks to an agent, which then forwards malicious instructions to another agent using different communication methods like Google's Agent-to-Agent (A2A) protocol. The technique represents a special form of indirect prompt injection that targets specific agents rather than the underlying language model directly.

1

Douglas McKee, director of vulnerability intelligence at Rapid7, explained the challenge: "AI agents give attackers a fresh set of connections to walk across. Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work."

1

Many special-purpose agents lack guardrails that might mitigate harmful consequences. Since MCP servers store credentials for each agent and agents are built to trust other internal agents, exploits that would normally be rejected by the LLM succeed through this trust gap. Each protocol was built assuming it operated independently, creating blind spots in the connections between systems.

Google and JPMorgan Chase Address High-Severity Vulnerabilities

Google's vulnerability carried a severity rating of 8.0 out of 10. The flaw in Google's MCP Toolbox for Databases (googleapis/mcp-toolbox) initialized its HTTP client without a CheckRedirect policy and failed to validate target IP addresses. CVE-2026-14540 affects versions 0.3.0 to 1.4.0.

2

Mohiuddin explained: "A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker's behalf." Google's fix involved applying allow-lists of IP ranges and block lists, rejecting unsafe base URLs at startup instead of on first request. "That is what a real SSRF guard looks like," Mohiuddin noted.

1

JPMorgan Chase's open-source repository included a documentation-search MCP server where one tool checked domains against an allowlist while its sibling fetched any URL the caller supplied. JPMorgan forked the component from an AWS project that never fetched caller URLs at all. JPMorgan's Responsible Disclosure team confirmed the medium-severity finding and deployed a fix.

2

Government Systems and Five Unpatched US Federal Servers

Weaviate restricted its Google module's endpoint settings to Google API hosts. DINUM's official MCP server for France's open-data platform fetched URLs supplied by data producers, which could point at internal or cloud metadata addresses. Its fix, titled "harden SSRF on external APIs," credits Syed Anas Mohiuddin.

2

In Tangerang's Wazuh MCP server, a tool advertised SSRF protection but only rejected literal IP addresses without resolving hostnames, according to a high-severity advisory published on 3 September. Rapid7 fixed CVE-2026-97228 in its Bulk Export MCP server, a GraphQL injection vulnerability rated at 2.7 severity.

1

2

On 2 September, Mohiuddin privately reported issues in five MCP servers under the US General Services Administration's Technology Transformation Services. These include servers for Veterans Affairs benefits claims, CMS Blue Button, regulations.gov, USASpending, and CDC PLACES. All five remain in triage without fixes.

2

In the Veterans Affairs case, the server logs full error responses from the benefits API without redaction. These can contain a veteran's name, Social Security number, date of birth, and address. Mohiuddin is withholding code-level details until maintainers patch the servers.

2

Why This Structural Flaw in MCP Matters for AI Adoption

Markus Vervier, researcher at X41 D-Sec who has also devised AI attacks exploiting MCP, describes the technique as indirect prompt injection. "The fact that the malicious prompt can come from a different protocol (e.g., A2A) and manifests when used over another protocol is not strictly required for such attacks to work. It is, of course, unexpected and hard to mitigate in general," Vervier told Ars Technica.

1

The fact that protocol pivoting worked across five organizations with nothing in common except Model Context Protocol usage is significant. MCP is new yet already deployed everywhere before sufficient testing and hardening. Organizations rushing to build sprawling agentic architectures have abandoned zero-trust principles, where networks verify every connection regardless of source.

1

This creates fresh opportunities for attackers to make agents take unauthorized actions like exfiltrating database contents and sensitive personal information. In the past five months alone, Google and four other organizations acknowledged vulnerabilities exploiting one agent to spread harmful instructions to other internal agents. Trust or authorization gets lost in translation between protocols, and well-crafted prompts targeting the right agent lead to server-side request forgery that causes web servers to make unauthorized network requests.

1

Mohiuddin will present these findings at MCPCon North America in San Jose on 23 October, providing organizations an opportunity to understand how to secure their AI agent deployments against these emerging threats.

2

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved