
What happened
Researcher Syed Anas Mohiuddin found that trust gaps in MCP let a malicious prompt move from one AI agent to another at Google, JP Morgan Chase, Weviate, Rapid7, and two governments.
Why it matters
In these attacks, a poisoned message picked up by one internal agent was trusted and executed by the next, so the damage spread along a chain the attackers did not have to build.
What to watch
The Rapid7 flaw CVE-2026-97228 was only rated 2.7 out of 10 and has been fixed, while Google's fix uses an IP allow-list; the test is whether other MCP operators adopt equivalent defenses.
WHO IT HITSSecurity teams and AI platform engineers running internal agents over MCP are the most exposed, because the flaws let an attacker pivot from one agent to the next inside the same network. Organizations that have delegated translation, data analysis, or similar tasks to such agents may need to re-examine whether those agents are trusted too broadly.
Summaries like this, in your inbox every morning.
In the past five months, five organizations with little in common apart from their use of AI agents have acknowledged vulnerabilities that let one internal agent feed harmful instructions to others. The technique is a specialized form of prompt injection that goes after an agent — say, one handling translation or data analysis — rather than the underlying text model. Those agents often have lax or missing guardrails, so they pass the instructions down the chain, and the next agent follows them because it explicitly trusts the first.
That trust architecture is what the fixes have to address. MCP servers hold credentials for each agent, and agents are designed to trust every other internal agent, so a request the text model itself would have rejected can still succeed. In many cases, well-crafted prompts aimed at the right agent lead to server-side request forgery, where a web server makes unauthorized network requests. Rapid7's Douglas McKee described the chain as every piece doing exactly what it was designed to do, with each protocol checking its own front door while nobody watches the hallway in between. Markus Vervier of X41 D-Sec argues the better term remains indirect prompt injection, and he calls the cross-protocol path unexpected and hard to mitigate in general.
The stakes hinge on how quickly the wider field replicates the fixes made in the two named cases. Mohiuddin's "protocol pivoting" label matters because, as McKee put it, a name is what gets defenders and standards bodies to design for a threat. The underlying bugs — injection and server-side request forgery — are old and well understood, but the rush to build sprawling agent architectures has set aside a core security principle: zero trust, under which networks assume some nodes may already be compromised and require authorization before sensitive transactions. Whether organizations reinstate that assumption for their agents, rather than trusting them by default, is likely to determine how far these attacks travel.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.