MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Independent researcher Syed Anas Mohiuddin demonstrated that MCP, the de‑facto standard for internal AI‑agent communication, can be hijacked to forward crafted prompts from one agent to another. By targeting a translation or data‑analysis agent that lacks strict input validation, he caused the downstream agent to execute a server‑side request forgery (SSRF). The proof‑of‑concept spanned five unrelated entities—Google, JP Morgan Chase, Weviate, Rapid7, France’s interministerial digital directorate, and a U.S. federal agency—showing that the vulnerability is protocol‑wide rather than product‑specific. Google’s MCP toolbox (googleapis/mcp‑toolbox) earned a CVE‑2026‑97228 rating of 8 because its HTTP client omitted a CheckRedirect policy and failed to verify target IPs, allowing a malicious path parameter to redirect requests to internal services. Rapid7’s MCP server received a modest 2.7 severity rating, yet both cases illustrate that an attacker who injects a prompt into one trusted agent can “pivot” the exploit across the agent network.
This discovery arrives as enterprises race to embed large‑language‑model agents into everything from customer‑support bots to internal analytics pipelines. MCP, along with emerging protocols such as Google’s Agent‑to‑Agent (A2A) and the Agent Network Protocol, has been adopted before comprehensive security vetting. The attacks are essentially a modern incarnation of classic injection and SSRF bugs, but they exploit the implicit trust that agents place in one another—a trust model that conflicts with the zero‑trust principle long advocated for network design. Companies are prioritizing speed and functionality over rigorous authentication between agents, leaving a wide attack surface that spans multiple vendors and internal services.
The fallout forces security teams to treat any LLM‑generated output as hostile input, regardless of the originating agent. Immediate mitigations include enforcing strict redirect handling, IP allow‑lists, and per‑agent authentication checks before delegating tasks. In the longer term, standards bodies will likely codify “protocol pivoting” as a distinct threat class, prompting vendors to embed zero‑trust checks directly into MCP implementations. Watch for rapid patch cycles from Google and Rapid7, and expect auditors to begin demanding proof of agent‑to‑agent guardrails in compliance reviews.
Key Takeaways
MCP’s design assumes universal trust among internal agents, a premise that enables protocol‑pivoting attacks across unrelated organizations.
Google’s MCP toolbox flaw (CVE‑2026‑97228) received an 8‑severity rating due to missing redirect and IP validation, while Rapid7’s similar issue scored only 2.7, highlighting inconsistent risk assessments.
The attacks demonstrate that classic SSRF and injection techniques remain effective when repurposed for AI‑agent pipelines, underscoring the need for zero‑trust controls at every delegation step.
Vendors and standards bodies are expected to formalize mitigations for “protocol pivoting,” making explicit authentication and input sanitization mandatory for future agent communication protocols.
About the Source
This analysis is based on reporting by Ars Technica. Here is a short excerpt for context:
Trust gaps in the new protocol spread malicious prompts from one agent to another.Read the original at Ars Technica