Agents

Flaws in Google and Rapid7 MCP Tools Expose AI Agents

Security researchers have exposed vulnerabilities in the Model Context Protocol that allow attackers to hijack interconnected AI agents across major organizations like Google.

Ars Technica AI1 day agoAgents
Image: Ars Technica AI

Independent security researcher Syed Anas Mohiuddin has demonstrated a new class of vulnerabilities targeting the Model Context Protocol (MCP) and other agent-to-agent communication standards. Dubbed "protocol pivoting," the technique exploits the inherent trust between connected AI agents to bypass traditional large language model guardrails. Mohiuddin successfully tested these proof-of-concept attacks against systems at Google, JP Morgan Chase, Weaviate, Rapid7, the US federal government, and the French government's interministerial digital directorate.

The vulnerabilities varied in severity across the affected organizations. At Rapid7, the flaw tracked as CVE-2026-97228 received a minor severity rating of 2.7 out of 10 and was patched last month. In contrast, a vulnerability in Google's database toolbox, known as googleis/mcp-toolbox, was rated a far more severe 8.0. This flaw occurred because the toolbox initialized its HTTP client without a CheckRedirect policy and failed to validate target IP addresses, allowing attackers to trigger server-side request forgery (SSRF) by forcing the server to follow redirects to internal endpoints. Google resolved the issue by implementing IP address allow-lists and block-lists.

The root of the issue lies in the rapid, unhardened adoption of agentic architectures that abandon zero-trust security principles. When an agent receives a malicious prompt, it often passes the instruction to another internal agent. Because these systems are designed to trust internal communications implicitly, the receiving agent executes the command without verification. While Mohiuddin views this as a distinct multi-step protocol pivoting attack, other experts, like Markus Vervier of X41 D-Sec, classify it as a form of indirect prompt injection that manifests across different communication protocols.

For AI developers and enterprise security teams, these findings highlight a critical blind spot in agent security. Douglas McKee, director of vulnerability intelligence at Rapid7, warns that developers must treat any data passed from an LLM to an internal tool as "input from a stranger on the internet." To secure these pipelines, practitioners must implement strict input validation, enforce authorization checks between individual agents, and move away from the assumption that internal network traffic is inherently safe.

This is our own summary of reporting by Ars Technica AI

More in Agents