RESEARCH · RESEARCH · #1575
Researcher finds 'protocol pivoting' vulnerabilities in MCP that enable agent-to-agent exploits
Independent researcher Syed Anas Mohiuddin demonstrated a class of attacks he calls “protocol pivoting” that exploits trust gaps in the Model Context Protocol (MCP) to pass malicious instructions between AI agents; he tested agents from Google, Rapid7, JP Morgan Chase, Weviate, the French interministerial digital directorate and US federal systems. Mohiuddin’s proofs-of-concept include server-side request forgery (SSRF) and prompt-injection chains; Rapid7 patched CVE-2026-97228 (severity 2.7) and Google fixed an issue in googleapis/mcp-toolbox (rated higher) by adding IP allow-lists and stricter URL validation.
KEY POINTS
- Independent researcher Syed Anas Mohiuddin demonstrated a class of attacks he calls “protocol pivoting” that exploits trust gaps in the Model Context Protocol (MCP) to pass malicious instructions between AI agents; he tested agents from Google, Rapid7, JP Morgan Chase, Weviate, the French interministerial digital directorate and US federal systems.
- Mohiuddin’s proofs-of-concept include server-side request forgery (SSRF) and prompt-injection chains; Rapid7 patched CVE-2026-97228 (severity 2.7) and Google fixed an issue in googleapis/mcp-toolbox (rated higher) by adding IP allow-lists and stricter URL validation.
- Because MCP is being widely adopted for inter-agent communication and often lacks agent-level guardrails, protocol pivoting lets attackers escalate from one protocol to another and perform exfiltration or SSRF that bypasses per-agent checks.
WHY IT MATTERS
Because MCP is being widely adopted for inter-agent communication and often lacks agent-level guardrails, protocol pivoting lets attackers escalate from one protocol to another and perform exfiltration or SSRF that bypasses per-agent checks.