Google, JPMorgan Chase and several other organizations have fixed flaws that let an attacker turn one AI agent inside a network against the agents around it, according to findings by an independent researcher that Ars Technica reported on Monday.

The researcher, Syed Anas Mohiuddin, found that a planted instruction could pass from agent to agent because the agents are built to trust one another. Agents made for narrow jobs, like translation or data analysis, often had weak guardrails or none, so they forwarded instructions that the underlying language model might have refused. His attacks ran through the Model Context Protocol, or MCP, a standard that connects AI apps and agents to tools and to each other inside corporate networks. In many cases, Ars reported, a well-made prompt aimed at the right agent ended in server-side request forgery, a bug that gets a server to send network requests it isn’t supposed to.

Accounts differ on exactly who was affected. Ars said Google and four other organizations had acknowledged vulnerabilities over the past five months, and it listed agents Mr. Mohiuddin tested at Google, JPMorgan Chase, Weaviate, Rapid7, France’s interministerial digital directorate and the U.S. federal government. [The Next Web reported](<https://thenextweb.com/news/mcp-flaw-ssrf-google-jpmorgan-dinum-protocol-pivoting>) that Google, JPMorgan Chase, Weaviate, the French directorate, known as DINUM, and the city government of Tangerang, Indonesia, had each fixed the same kind of flaw.

The federal cases are still open. Mr. Mohiuddin has said he privately reported problems in five MCP servers run by the General Services Administration’s Technology Transformation Services on Sept. 2, and that all five were still in triage.

Google’s bug was the most serious. It sat in the company’s MCP toolbox for databases, whose HTTP client was set up without a CheckRedirect policy, the settings that tell a server what to do when a web address errors out or redirects somewhere else. The client also didn’t check target IP addresses. The flaw, CVE-2026-14540, affected versions 0.3.0 through 1.4.0 and carries a score of 8.0 under the newer CVSS standard and 6.1 under the older one, [according to the CVE record](<https://app.opencve.io/cve/CVE-2026-14540>).

“A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mr. Mohiuddin said. Google’s [fix, merged on June 18](<https://github.com/googleapis/mcp-toolbox/pull/3448>) and shipped in version 1.5.0, added allow lists and block lists of IP ranges. “It rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done,” he said.

Rapid7’s flaw, CVE-2026-97228, was rated 2.7 out of 10. The company fixed it last month.

Mr. Mohiuddin calls the technique “protocol pivoting.” In [his paper](<https://zenodo.org/records/20371152>), MCP handles tool access, while separate standards like Google’s Agent-to-Agent protocol, or A2A, and the newer Agent Network Protocol handle handoffs between agents, and each was designed as if it ran alone. He describes the attack as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.” He has also filed an [Internet-Draft with the IETF](<https://datatracker.ietf.org/doc/draft-mohiuddin-mcp-security-considerations/>) that says the MCP specification sets no normative security requirements.

Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars that a poisoned piece of content can travel down a chain of agents as an ordinary delegated task. “Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch,” he said. “Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.”

Markus Vervier, a researcher at X41 D-Sec who has built his own attacks on MCP, doesn’t think the technique needs a new name. He told Ars it was a simple subclass of prompt injection.

“For me this is indirect prompt injection,” Mr. Vervier said. “The fact that the malicious prompt can come from a different protocol (e.g., A2A) and manifests when used over another protocol is not strictly required for such attacks to work. It is, of course, unexpected and hard to mitigate in general.”

Ars wrote that companies rushing to wire up agents had dropped zero trust, a design rule that assumes some machines on a network are already compromised and makes each one get authorization before sensitive exchanges with the others. Security executives have pushed the same point, urging companies to treat AI agents as insiders.

“The lesson I’d want people to take away is that anything passed from an LLM to your tool should be treated like input from a stranger on the internet, because in a prompt injection scenario that’s exactly what it is,” Mr. McKee said.