AI NewsInfrastructureReported
Researcher found MCP trust gaps in five organisations, including Google and Rapid7
Ars Technica reported on 5 October that independent researcher Syed Anas Mohiuddin found MCP trust gaps in agents at Google, Rapid7, JP Morgan Chase, Weviate and the French government that let a malicious prompt move from one agent to another.

Image: Ars Technica
Why it mattersAn MCP server trusts the agents on the other side of it, so a prompt injection against one agent can walk into every tool the next agent is allowed to call.
A prompt injection against one agent used to stop there. Ars Technica reported on 5 October that an independent researcher, Syed Anas Mohiuddin, has shown it can walk down a chain of agents that trust each other, and that five organisations have acknowledged the bug in the past five months.
The organisations are Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. The common piece is Model Context Protocol, the standard that connects an agent to tools and to other agents inside a network. Mohiuddin tested the agents and reported each finding to the owner.
What the attacker does
Mohiuddin's name for the class is "protocol pivoting". An attacker plants instructions in content that one agent reads, that agent forwards them to a second agent through MCP or a protocol such as Google's Agent-to-Agent (A2A), and the second agent runs them because it trusts the first one. The guardrails that would normally stop a prompt injection at the LLM are often not present in the special-purpose agent that handles the second step.
In many of Mohiuddin's cases, the result is a server-side request forgery, meaning the attacker gets the trusted agent to send network requests on their behalf.
The two acknowledged bugs with numbers
The vulnerability Mohiuddin found at Rapid7 is tracked as CVE-2026-97228 and was rated 2.7 out of 10 for severity. Ars Technica says Rapid7 fixed it last month.
The Google bug was rated 8 out of 10. It sat in googleapis/mcp-toolbox, which Ars Technica says started its HTTP client with no CheckRedirect policy and did not validate target IP addresses. Mohiuddin wrote that a crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests from there. Google's fix applied an allow-list of IP ranges and a block-list, and now rejects an unsafe base URL at startup rather than on the first request.
What a team running MCP should do
Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars Technica that "anything passed from an LLM to your tool should be treated like input from a stranger on the internet". That is the practical take-away for a team running MCP servers: an agent-to-agent request is a user request, and the server has to authorise it, not trust it on sight. The researcher Markus Vervier at X41 D-Sec disagreed on the name, telling Ars Technica this is indirect prompt injection and nothing more, but did not disagree on the risk.
Source
Dan Goodin, Ars Technica, 5 October 2026. Mohiuddin's write-up is here.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.
