MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Independent researcher Syed Anas Mohiuddin has demonstrated proof-of-concept attacks that exploit trust gaps in the Model Context Protocol (MCP), the standard by which AI apps and agents communicate inside an internal network. According to the report, Google, Rapid7, and three other organizations—described as having little in common except their use of AI agents—acknowledged vulnerabilities over the past five months that let one compromised agent spread harmful instructions to other internal agents.
The technique is a special form of prompt injection that targets a particular agent, such as one for translation or data analysis, rather than the underlying LLM. Guardrails inside such agents, if present, are often lax, and the agents forward instructions down the chain; because each downstream agent explicitly trusts the one before it, it follows the directions. Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government.
CVE-2026-97228, the vulnerability found in Rapid7's network, had a severity rating of 2.7 out of 10; Rapid7 fixed it last month. The Google vulnerability was rated 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client without a CheckRedirect policy and failing to validate target IP addresses, which Mohiuddin said could let a crafted path parameter make the toolbox follow a redirect to an internal endpoint and send requests on an attacker's behalf. Google's fix applied an allow-list of IP ranges and block lists; Mohiuddin said it rejects an unsafe base URL at startup and called it more work than most MCP servers have done.
Mohiuddin calls the attack class "protocol pivoting," describing it as a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol, such as Google's Agent-to-Agent (A2A) protocol or the Agent Network Protocol. Markus Vervier, a researcher at X41 D-Sec, said the better term remains "prompt injection" and that Mohiuddin's technique is a simple subclass of it. "For me this is indirect prompt injection," Vervier said, adding that the malicious prompt coming from a different protocol is not strictly required for such attacks to work, but is unexpected and hard to mitigate in general.
Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars that AI agents give attackers a fresh set of connections to walk across, and that each protocol was built assuming it lived on its own. Mohiuddin and McKee both characterized the underlying bugs as injection and server-side request forgery.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Trust gaps in the new protocol spread malicious prompts from one agent to another.