Tuesday, 6 October 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 6 October 2026 at 02:25

Structural flaw found in MCP protocol used for AI agent-to-agent communication

A researcher has shown that the widely adopted Model Context Protocol (MCP) lets attackers compromise one AI agent and use it to spread malicious instructions to other internal agents. Google and four other organizations, including JP Morgan Chase and Rapid7, have confirmed related flaws.

Foto: Ars Technica

Over the past five months, independent researcher Syed Anas Mohiuddin has uncovered security weaknesses in AI agent deployments at several organizations, including Google, JP Morgan Chase, Weviate, Rapid7, France's interministerial digital directorate, and the US federal government. All of the flaws exploit trust gaps in the Model Context Protocol (MCP), a standard used by AI apps and agents to communicate within internal networks.

The attack works by tricking a single specialized agent — for example one handling translation or data analysis — into accepting a malicious instruction, which it then passes along to another agent further down the chain. Because the receiving agent implicitly trusts whoever delegated the task, it carries out the instruction without additional scrutiny. In many cases, this leads to server-side request forgery (SSRF), causing a web server to make unauthorized network requests.

A vulnerability found in Rapid7's network, CVE-2026-97228, received a low severity score of 2.7 out of 10 and was patched last month. A more serious flaw affecting Google, rated 8 out of 10, stemmed from Google's MCP toolbox for databases initializing its HTTP client without a redirect-checking policy and without validating target IP addresses, allowing a crafted request parameter to redirect traffic to internal endpoints. Google fixed the issue by applying allow-lists and block-lists for IP ranges.

Mohiuddin calls this class of attack 'protocol pivoting' — a multi-step technique in which an attacker gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities reachable only through a different one, such as Google's Agent-to-Agent (A2A) protocol. Other researchers, including Markus Vervier of X41 D-Sec, argue the more accurate label is 'indirect prompt injection.' Rapid7's Douglas McKee said organizations should treat anything an LLM passes to a tool as they would input from a stranger on the internet, since in a prompt injection scenario that is effectively what it is.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category

Structural flaw found in MCP protocol used for AI agent-to-agent communication — Rīga TV