
Security researchers have documented a pattern of vulnerabilities affecting multiple organizations’ AI agent systems, revealing significant trust gaps in the Model Context Protocol, a standard used for internal agent-to-agent communications. Over the past five months, Google, JP Morgan Chase, Weviate, Rapid7, France’s interministerial digital directorate, and U.S. federal agencies have all acknowledged security issues exploiting these weaknesses.
The vulnerability class, termed “protocol pivoting” by independent researcher Syed Anas Mohiuddin, involves a specialized form of prompt injection targeting individual agents rather than language models directly. An attacker can craft malicious instructions that, when processed by one agent, get forwarded to other agents in the chain. Because these downstream agents are designed to trust instructions from upstream agents, they execute the harmful directives. Many agents lack robust guardrails, and since MCP servers store credentials with implicit trust relationships between agents, exploits that would normally be rejected succeed without additional authentication.
The attacks frequently result in server-side request forgery vulnerabilities, enabling unauthorized network requests. One notable example involved Google’s MCP database toolbox, which initialized its HTTP client without proper redirect policies and failed to validate IP addresses, allowing crafted parameters to redirect requests to internal endpoints. Google subsequently implemented IP allowlists and blocklists to mitigate the issue. A vulnerability in Rapid7’s network carried a lower severity rating but demonstrated the same underlying pattern.
Security experts attribute the proliferation of these issues to MCP’s recent emergence and rapid adoption before adequate security testing and hardening could occur. Organizations building extensive agent architectures have overlooked fundamental zero-trust security principles, which assume nodes may be compromised and require authorization for sensitive operations. The fundamental bugs—injection and server-side request forgery—represent longstanding security issues, though their manifestation in agent environments requires defenders to treat all LLM-generated outputs as potentially hostile input.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI