A new class of vulnerability exposed structural weaknesses in the Model Context Protocol (MCP), a standard used by AI agents to communicate within internal networks. In the past five months, Google and four other organisations have acknowledged flaws that let an attacker use one agent inside a network to cascade malicious prompts to other agents.
The attacks hinge on “protocol pivoting” or prompt injection that targets a specific agent (for example, a translation or data-analysis agent) rather than the large language model itself. Because MCP servers store credentials for each agent and agents are designed to trust one another, an exploit aimed at one link can escalate as instructions travel through the chain, potentially causing server-side requests and unintended actions.
Independent researcher Syed Anas Mohiuddin demonstrated attacks across organisations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate and the US federal government. The Rapid7 case, CVE-2026-97228, was a relatively low-severity 2.7, fixed last month.
Google’s exposure was more severe (rating 8) and stemmed from the MCP toolbox for databases (googleapis/mcp-toolbox) failing to enforce a proper CheckRedirect policy and not validating target IP addresses, allowing a crafted path parameter to redirect to an internal endpoint. Google’s mitigation involved IP allow-lists and block lists and preventing unsafe base URLs at startup.
Experts note that, in practice, many MCP deployments lack robust zero-trust controls, so responses emphasise treating inter-agent inputs as potentially hostile and applying traditional SSRF and prompt-injection mitigations across all involved protocols.