"Protocol pivoting": researcher Syed Anas Mohiuddin shows prompt-injected AI agents passing malicious tasks to trusted internal agents across MCP and A2A; Google, Rapid7 (CVE-2026-97228) and three other organisations acknowledged flaws in five months
Ars Technica reported on 5 October 2026 that, over the past five months, Google and four other organisations have acknowledged vulnerabilities found by independent researcher Syed Anas Mohiuddin in which one AI agent inside a network is tricked into handing harmful instructions to other internal agents. He tested agents from organisations including Google, JPMorgan Chase, Weaviate, Rapid7, France's interministerial digital directorate and the US federal government. The attacks rely on trust gaps in the Model Context Protocol (MCP): special-purpose agents such as translation or data-analysis agents often lack guardrails, MCP servers hold credentials for each agent, and downstream agents trust whatever an upstream agent delegates, so instructions an LLM would normally reject get carried out, often ending in server-side request forgery. He calls the class "protocol pivoting", where access gained through one protocol is used to reach capabilities only available through another, such as Google's Agent-to-Agent (A2A) protocol. Rapid7's bug, CVE-2026-97228, was rated 2.7 and fixed in September; Google's MCP Toolbox for Databases flaw (CVE-2026-14540, rated 8.0, covered separately on this desk) followed redirects to internal endpoints and was fixed with IP allow and block lists. X41 D-Sec's Markus Vervier told Ars this is a subclass of indirect prompt injection. Rapid7's Douglas McKee said anything an LLM passes to a tool should be treated like input from a stranger on the internet. Source: Ars Technica.
- Product
- Multi-agent AI systems using MCP, A2A and similar agent protocols
- Versions
- n/a — research across several vendors; individual fixes per vendor (Rapid7 CVE-2026-97228 fixed September 2026; Google MCP Toolbox 1.5.0+)
- CVSS
- 2.7 (CVE-2026-97228, Rapid7); 8.0 (CVE-2026-14540, Google)
- Exploited in Australia?
- unknown
- Patch to
- Treat every task one agent delegates to another as untrusted input: give each agent its own narrowly scoped credentials rather than shared MCP server secrets, require authorisation for sensitive actions between agents, put SSRF guards (redirect policies, IP allow and block lists) on any agent or tool that fetches URLs, and log agent-to-agent calls so a chain can be traced.
Primary: Ars Technica — Vulnerability in agents from Google and others exposes structural flaw in MCP (5 Oct 2026) · Vendor: Cyberstack — Google MCP Toolbox CVE-2026-14540 SSRF (related card) · CVE: CVE-2026-97228, CVE-2026-14540
