Tuesday, Oct 6 | --:--
Back to home

Same MCP Trust-Boundary Bug Across Google, JPMorgan, Weaviate and Two Governments

Ars Technica reports that independent researcher Syed Anas Mohiuddin has, over five months, had a class of Model Context Protocol server flaws confirmed and fixed at unrelated organizations. Attacker text read by one agent can be passed as a delegated task to a trusted peer, which then performs SSRF or another privileged action from inside the network — a pattern he calls protocol pivoting. Federal findings remain in triage and are described only at class level.

Times of AI Desk 6 min read United States / Europe / Indonesia View as Markdown
Cover illustration for Same MCP Trust-Boundary Bug Across Google, JPMorgan, Weaviate and Two Governments

Agent stacks are being wired together with MCP and A2A faster than anyone is checking the trust boundary between them — and the same old web bug keeps showing up.

Ars Technica (Dan Goodin, October 5, 2026) reports that independent researcher Syed Anas Mohiuddin has, over about five months, had a class of Model Context Protocol (MCP) server flaws confirmed and fixed by organizations that share little but the protocol: Google, JPMorgan Chase, Weaviate, France’s DINUM (data.gouv.fr MCP), and Indonesia’s Tangerang city government. In his framing — which Ars and Rapid7’s Douglas McKee amplify — attacker text planted in content one agent reads gets passed on as a normal delegated task to another agent that trusts it. That second agent then carries out server-side request forgery (SSRF) or another privileged action from inside the network. He calls the multi-protocol escalation “protocol pivoting.” X41 D-Sec’s Markus Vervier told Ars it is better understood as a subclass of indirect prompt injection.

What vendors fixed (attributed)

In Mohiuddin’s own write-up (self-published; vendor confirmations are his account plus the CVE/advisory IDs he cites), Google’s MCP Toolbox for Databases lacked a redirect policy and IP validation — assigned CVE-2026-14540, CVSS 8.0, and fixed with connection-time resolved-address checks and IP allow/block lists. Ars reports Google’s severity as 8 without naming the CVE in the inspected text; the CVE ID here is attributed to his write-up. JPMorgan’s open-source docs MCP server, in his account, dropped an allowlist on a related() fetch after forking AWS code; a fix was deployed. Weaviate, DINUM and Tangerang fixed similar SSRFs. Rapid7 published related CVE-2026-97228 (CVSS 2.7), fixed last month.

Five MCP servers built for U.S. federal agencies (including a VA benefits-related server) were reported Sept. 2 and remain in triage. Those findings are described only at class level here — no exploit steps, payloads or reproduction detail.

Why scanners miss it

McKee’s point, quoted by Ars: each protocol checks its own front door while nobody watches the hallway. Dependency scanners do not see tool arguments that arrive as delegated agent text. Most individual bugs in the public set are fixed and moderate. What is news is the cross-vendor pattern, largely the researcher’s framing with vendor confirmations — not a single new zero-day.

Limits

  • Pattern and CVE-2026-14540 details: researcher’s write-up + Ars secondary. Advisories were not re-opened independently here.
  • Federal findings: unpatched / in triage — class description only; no code-level detail.
  • Vervier frames this as indirect prompt injection, not a wholly new class.
  • Mohiuddin presents at MCPCon North America Oct. 23.

Sources

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading