Tech Meridian ← LIVE FEED
PROMY MERIDIAN RU

RESEARCH · RESEARCH · #1575

Researcher finds 'protocol pivoting' vulnerabilities in MCP that enable agent-to-agent exploits

Independent researcher Syed Anas Mohiuddin demonstrated a class of attacks he calls “protocol pivoting” that exploits trust gaps in the Model Context Protocol (MCP) to pass malicious instructions between AI agents; he tested agents from Google, Rapid7, JP Morgan Chase, Weviate, the French interministerial digital directorate and US federal systems. Mohiuddin’s proofs-of-concept include server-side request forgery (SSRF) and prompt-injection chains; Rapid7 patched CVE-2026-97228 (severity 2.7) and Google fixed an issue in googleapis/mcp-toolbox (rated higher) by adding IP allow-lists and stricter URL validation.

KEY POINTS

  1. Independent researcher Syed Anas Mohiuddin demonstrated a class of attacks he calls “protocol pivoting” that exploits trust gaps in the Model Context Protocol (MCP) to pass malicious instructions between AI agents; he tested agents from Google, Rapid7, JP Morgan Chase, Weviate, the French interministerial digital directorate and US federal systems.
  2. Mohiuddin’s proofs-of-concept include server-side request forgery (SSRF) and prompt-injection chains; Rapid7 patched CVE-2026-97228 (severity 2.7) and Google fixed an issue in googleapis/mcp-toolbox (rated higher) by adding IP allow-lists and stricter URL validation.
  3. Because MCP is being widely adopted for inter-agent communication and often lacks agent-level guardrails, protocol pivoting lets attackers escalate from one protocol to another and perform exfiltration or SSRF that bypasses per-agent checks.

WHY IT MATTERS

Because MCP is being widely adopted for inter-agent communication and often lacks agent-level guardrails, protocol pivoting lets attackers escalate from one protocol to another and perform exfiltration or SSRF that bypasses per-agent checks.

SOURCES & TIMELINE

1