# Same MCP Trust-Boundary Bug Across Google, JPMorgan, Weaviate and Two Governments

Times of AI Desk · 2026-10-05 · Security

[https://timesof.ai/2026/10/mcp-protocol-pivoting-cross-agent-ssrf](https://timesof.ai/2026/10/mcp-protocol-pivoting-cross-agent-ssrf)

> Ars Technica reports that independent researcher Syed Anas Mohiuddin has, over five months, had a class of Model Context Protocol server flaws confirmed and fixed at unrelated organizations. Attacker text read by one agent can be passed as a delegated task to a trusted peer, which then performs SSRF or another privileged action from inside the network — a pattern he calls protocol pivoting. Federal findings remain in triage and are described only at class level.

Agent stacks are being wired together with **MCP** and **A2A** faster than anyone is checking the trust boundary between them — and the same old web bug keeps showing up.

**Ars Technica** (Dan Goodin, **October 5, 2026**) reports that independent researcher **Syed Anas Mohiuddin** has, over about five months, had a class of **Model Context Protocol (MCP)** server flaws confirmed and fixed by organizations that share little but the protocol: **Google**, **JPMorgan Chase**, **Weaviate**, France’s **DINUM** (data.gouv.fr MCP), and Indonesia’s **Tangerang** city government. In his framing — which Ars and Rapid7’s Douglas McKee amplify — attacker text planted in content one agent reads gets passed on as a normal delegated task to another agent that trusts it. That second agent then carries out **server-side request forgery (SSRF)** or another privileged action from inside the network. He calls the multi-protocol escalation **“protocol pivoting.”** X41 D-Sec’s **Markus Vervier** told Ars it is better understood as a subclass of **indirect prompt injection**.

## What vendors fixed (attributed)

In Mohiuddin’s own write-up (self-published; vendor confirmations are his account plus the CVE/advisory IDs he cites), **Google’s MCP Toolbox for Databases** lacked a redirect policy and IP validation — assigned **CVE-2026-14540**, CVSS **8.0**, and fixed with connection-time resolved-address checks and IP allow/block lists. Ars reports Google’s severity as **8** without naming the CVE in the inspected text; the CVE ID here is attributed to **his write-up**. **JPMorgan’s** open-source docs MCP server, in his account, dropped an allowlist on a `related()` fetch after forking AWS code; a fix was deployed. **Weaviate**, **DINUM** and **Tangerang** fixed similar SSRFs. **Rapid7** published related **CVE-2026-97228** (CVSS **2.7**), fixed last month.

Five MCP servers built for **U.S. federal** agencies (including a VA benefits-related server) were reported **Sept. 2** and remain **in triage**. Those findings are described **only at class level** here — no exploit steps, payloads or reproduction detail.

## Why scanners miss it

McKee’s point, quoted by Ars: each protocol checks its own front door while nobody watches the hallway. Dependency scanners do not see tool arguments that arrive as delegated agent text. Most individual bugs in the public set are fixed and moderate. What is news is the **cross-vendor pattern**, largely the researcher’s framing with vendor confirmations — not a single new zero-day.

## Limits

- Pattern and CVE-2026-14540 details: **researcher’s write-up** + Ars secondary. Advisories were not re-opened independently here.
- Federal findings: **unpatched / in triage** — class description only; no code-level detail.
- Vervier frames this as indirect prompt injection, not a wholly new class.
- Mohiuddin presents at **MCPCon North America** Oct. 23.

## Sources

- [Ars Technica: MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of (October 5, 2026)](https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp/)
- [Syed Anas Mohiuddin: Protocol Pivoting, four months later](https://anas-security-portfolio.vercel.app/protocol-pivoting-update.html)
