Independent researcher Syed Anas Mohiuddin disclosed in an October 2026 update titled "Protocol Pivoting, four months later" that the same server-side request forgery flaw in Model Context Protocol servers has been confirmed and fixed by security teams at five unrelated organizations: Google, JPMorgan Chase, Weaviate, France's Interministerial Directorate for Digital Affairs, and the Tangerang City government in Indonesia3. The update also tallied two published CVEs and five findings in U.S. federal MCP servers that remain open.
Ars Technica reported that AI agents built on Model Context Protocol carry a structural vulnerability that lets an attacker compromise one agent and spread malicious instructions to every other agent in the chain1. Mohiuddin tested agent deployments at Google, JPMorgan Chase, Weviate, Rapid7 Inc., France's Interministerial Directorate for Digital Affairs, and the U.S. government, according to the report2.
How the attack works
Mohiuddin's method, which he calls "protocol pivoting," targets not the large language model itself but a specific agent, such as one handling translation or data analysis. He describes two failure modes: server-side request forgery, where an MCP server builds an outbound request from a URL supplied by an agent without checking where it resolves, and unsafe handling of upstream data, most visibly writing full upstream API responses into centralized logs without redaction. A downstream agent explicitly trusts the compromised upstream agent and follows its instructions, meaning an exploit that the LLM would have rejected succeeds in many cases.
Mohiuddin's May 2026 formal preprint, "Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems," published on Zenodo on May 24, 2026, presents three scenarios: MCP-to-Agent-to-Agent (A2A) privilege escalation via implicit trust delegation, A2A-to-MCP capability injection via malicious agent impersonation, and cross-protocol prompt injection chains.
Markus Vervier, a researcher at X41 D-Sec, told Ars Technica that Mohiuddin's technique is a simple subclass of prompt injection.
ANALYSIS The distinction matters: labeling the attack a prompt-injection subclass places it within a known threat category, but the cross-agent propagation mechanism is what differentiates it from single-model prompt injection.
Fixes and severity scores
Google merged fix pull request #3448 in the googleapis/mcp-toolbox repository on June 18, 2026, shipping in mcp-toolbox v1.5.0. The advisory rated the Google flaw High severity with a CVSS score of 8.0. The fix implements an SSRFGuard to prevent DNS-rebinding attacks, adds configurable allowPrivateNetworks, allowedIpRanges, and customBlockedIpRanges properties, and validates the configured BaseURL at initialization.
JPMorgan Chase's Responsible Disclosure team confirmed the finding as valid and deployed a fix; the vulnerability was in a documentation-search MCP server whose sibling related() tool fetched a caller-supplied URL server-side with no restriction. Weaviate listed Mohiuddin by name in its public Security Hall of Fame entry dated August 25, 2026, and merged a pull request restricting the Google module's apiEndpoint, region, and location settings to Google API hosts.
Rapid7 Inc. published CVE-2026-97228 on September 25, 2026, scoring it at 2.7 (Low) on the CVSS 3.1 scale; version 0.6.2 fixes the Rapid7 Bulk Export MCP issue by passing export id as a parameterized variable. France's datagouv/datagouv-mcp project merged pull request #126, "feat: harden SSRF on external APIs," on September 4, 2026.
U.S. federal exposure
Mohiuddin filed five findings as private GitHub Security Advisories on September 2, 2026, covering MCP servers under the GSA's Technology Transformation Services. The five advisories cover a Department of Veterans Affairs benefits-claims server, a CMS Blue Button server, a regulations.gov server, a USASpending server, and a CDC PLACES server. In the VA case, the server logs the full upstream benefits-API error body at ERROR level without redaction; those error bodies can contain a veteran's name, Social Security number, date of birth, and address. All five government findings remain in triage and are not fixed.
Mohiuddin built mcp-safeguard, an open-source scanner that tests MCP servers through their exposed tool surface without needing source code, checking for SSRF, excessive permissions, prompt-injection surfaces, information leakage, authentication gaps, and lifecycle bypass. As of the update, 16 GitHub security advisories published by projects' own maintainers credit Mohiuddin as reporter.
ANALYSIS The wide severity gap between the Google (CVSS 8.0) and Rapid7 Inc. (CVSS 2.7) vulnerabilities for the same class of flaw underscores that the risk depends heavily on what credentials and network access a given MCP agent holds, rather than on the protocol alone.