Researcher discloses "protocol pivoting" MCP prompt-injection attacks that spread between AI agents; Google and Rapid7 among organizations that patched flaws
Independent researcher Syed Anas Mohiuddin demonstrated proof-of-concept attacks on agents at Google, JP Morgan Chase, Weviate, Rapid7, the French government's digital directorate and the US federal government. The attacks exploit trust gaps in MCP and between protocols such as A2A. Vulnerabilities were acknowledged and fixed in at least two cases. Rapid7's CVE-2026-97228 (severity 2.7) was fixed last month. Google's googleapis/mcp-toolbox SSRF flaw (severity 8) was fixed with IP allow-lists and block lists, and the toolbox now rejects unsafe base URLs at startup. The researcher also coined the term "protocol pivoting".
Entities: Syed Anas Mohiuddin, Model Context Protocol (MCP), Google, googleapis/mcp-toolbox, Agent-to-Agent (A2A) protocol, Rapid7
0 primary
What happened
Independent researcher Syed Anas Mohiuddin showed proof-of-concept attacks, which he calls "protocol pivoting", in which a prompt injection in one AI agent is passed on to others through trust gaps in MCP and between protocols such as A2A. Targets named include agents at Google, JP Morgan Chase, Weviate, Rapid7, the French government's digital directorate and the US federal government. Fixes are confirmed in at least two cases: Rapid7's CVE-2026-97228 (severity 2.7, fixed last month) and a Google googleapis/mcp-toolbox server-side request forgery flaw (severity 8), now blocked with IP allow-lists and block lists and a startup check that rejects unsafe base URLs. The extraction lists no links to the original research, so this account comes from press coverage and we have not checked the primary material.
Why it matters
Teams that run MCP or A2A setups now have a named attack pattern and two vendor-confirmed examples to test against. The practical decisions are to check whether agents trust one another's output by default, to restrict which URLs tools can reach, and to update mcp-toolbox. The two confirmed fixes are one low-severity and one high-severity flaw, so the evidence shows real bugs in specific products. It does not show a broad, easily exploited weakness across the other named organisations. The impact on any given deployment depends on its architecture and is uncertain.
What is noise
The headline calling MCP "the riskiest protocol you've never heard of" is clickbait, and it is a superlative with no comparison behind it. Agents passing injected instructions to each other is a known risk, and "protocol pivoting" mostly puts a new name on it. The coverage also doesn't make clear which of the named organisations, beyond Google and Rapid7, had a confirmed flaw and which were only proof-of-concept targets. The claim that organisations have "abandoned zero-trust" is a general assertion without measured support.
Watch next
- 01Publication of the original research, with the proof-of-concept details, so the claims about JP Morgan Chase, Weviate, and the French and US government agents can be checked against primary evidence.
- 02Further CVEs or vendor advisories for MCP servers and A2A implementations that cite agent-to-agent injection, and whether other vendors confirm fixes. Also check whether the two cited CVEs appear in public databases with the stated severities.
- 03Changes to the MCP and A2A specifications or reference implementations, such as authentication between agents, URL restrictions or trust boundaries, within the next few months.
Coverage
1 storyMore infrastructure signals
Full feed →- Anthropic commits $11.6B over seven years to Akamai for CPU-focused cloud infrastructure, with warrant tied to spending milestones25 Sept 202688
- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI discloses sandbox-escape and credential-leak incidents, confirms pause on tool-use for its most capable models26 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680