Tech Meridian ← ENTITY INDEX
PROMY MERIDIAN RU

COMPANY · ENTITY #14003

X41 D-Sec

Related event timeline, sources and context from the news index.

EVENT TIMELINE

1

RESEARCH · 1 SOURCE · Ars Technica

Researcher finds 'protocol pivoting' vulnerabilities in MCP that enable agent-to-agent exploits

Independent researcher Syed Anas Mohiuddin demonstrated a class of attacks he calls “protocol pivoting” that exploits trust gaps in the Model Context Protocol (MCP) to pass malicious instructions between AI agents; he tested agents from Google, Rapid7, JP Morgan Chase, Weviate, the French interministerial digital directorate and US federal systems. Mohiuddin’s proofs-of-concept include server-side request forgery (SSRF) and prompt-injection chains; Rapid7 patched CVE-2026-97228 (severity 2.7) and Google fixed an issue in googleapis/mcp-toolbox (rated higher) by adding IP allow-lists and stricter URL validation.

8.0