AIToday
Ars Technica AIPublished: Oct 6, 2026, 10:00 JST

Syed Anas Mohiuddin finds "protocol pivoting" flaws in AI agents

Syed Anas Mohiuddin finds "protocol pivoting" flaws in AI agents

3 Key Points

  1. What happened

    Researcher Syed Anas Mohiuddin found that trust gaps in MCP let a malicious prompt move from one AI agent to another at Google, JP Morgan Chase, Weviate, Rapid7, and two governments.

  2. Why it matters

    In these attacks, a poisoned message picked up by one internal agent was trusted and executed by the next, so the damage spread along a chain the attackers did not have to build.

  3. What to watch

    The Rapid7 flaw CVE-2026-97228 was only rated 2.7 out of 10 and has been fixed, while Google's fix uses an IP allow-list; the test is whether other MCP operators adopt equivalent defenses.

WHO IT HITSSecurity teams and AI platform engineers running internal agents over MCP are the most exposed, because the flaws let an attacker pivot from one agent to the next inside the same network. Organizations that have delegated translation, data analysis, or similar tasks to such agents may need to re-examine whether those agents are trusted too broadly.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

In the past five months, five organizations with little in common apart from their use of AI agents have acknowledged vulnerabilities that let one internal agent feed harmful instructions to others. The technique is a specialized form of prompt injection that goes after an agent — say, one handling translation or data analysis — rather than the underlying text model. Those agents often have lax or missing guardrails, so they pass the instructions down the chain, and the next agent follows them because it explicitly trusts the first.

That trust architecture is what the fixes have to address. MCP servers hold credentials for each agent, and agents are designed to trust every other internal agent, so a request the text model itself would have rejected can still succeed. In many cases, well-crafted prompts aimed at the right agent lead to server-side request forgery, where a web server makes unauthorized network requests. Rapid7's Douglas McKee described the chain as every piece doing exactly what it was designed to do, with each protocol checking its own front door while nobody watches the hallway in between. Markus Vervier of X41 D-Sec argues the better term remains indirect prompt injection, and he calls the cross-protocol path unexpected and hard to mitigate in general.

The stakes hinge on how quickly the wider field replicates the fixes made in the two named cases. Mohiuddin's "protocol pivoting" label matters because, as McKee put it, a name is what gets defenders and standards bodies to design for a threat. The underlying bugs — injection and server-side request forgery — are old and well understood, but the rush to build sprawling agent architectures has set aside a core security principle: zero trust, under which networks assume some nodes may already be compromised and require authorization before sensitive transactions. Whether organizations reinstate that assumption for their agents, rather than trusting them by default, is likely to determine how far these attacks travel.

FAQ
What is MCP?
It stands for Model Context Protocol, a standard that lets AI apps and agents communicate with each other inside an internal network. The vulnerabilities found in this story exploit how agents trust one another when using it.
Which organizations were affected?
Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government.
How severe were the vulnerabilities?
The Rapid7 flaw, tracked as CVE-2026-97228, had a severity rating of only 2.7 out of 10 and was fixed last month. The Google vulnerability was more severe, with a rating of 8.
Is there a fix?
Yes for the two named cases: Rapid7 fixed its flaw last month, and Google fixed its by applying an allow-list of IP ranges and block lists. Mohiuddin said Google's fix rejects an unsafe base URL at startup rather than on first request.
Ars Technica AIRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Next articleGemini Call for Me may expand to personal calls