READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Google, JPMorgan Chase and Two Governments Patch the Same AI Agent Security Flaw

Google, JPMorgan Chase and Two Governments Patch the Same AI Agent Security Flaw
Independent researcher Syed Anas Mohiuddin found the identical structural flaw in AI agent systems run by Google, JPMorgan Chase, Weaviate, Rapid7, and government agencies in France, the US and Indonesia. Each organization patched its own bug, but the researcher says the real problem is baked into how the Model Context Protocol handles trust between agents, not any single company's mistake.

AI agents are supposed to make enterprise software faster. Turns out they're also handing attackers a new hallway to walk down.

Over roughly the past five months, independent researcher Syed Anas Mohiuddin tested AI agent systems at Google, JPMorgan Chase, Weaviate, Rapid7, France's interministerial digital directorate (DINUM), and the US federal government, according to Ars Technica. Every one of them had the same structural weakness in how their AI agents talk to each other using the Model Context Protocol, or MCP.

MCP is the standard that lets different AI agents inside a company's network pass tasks and data to one another. Ars Technica reports that the flaw isn't a bug in any one AI model. It's a trust problem. One agent, say a translation tool, gets fed malicious text through a prompt injection. It then hands that poisoned instruction off to another agent, like a data analysis tool, which carries it out because it was built to trust anything coming from inside the network.

The specific bugs

The severity varied a lot. Rapid7's flaw, tracked as CVE-2026-97228, got a relatively mild 2.7 out of 10 rating, according to Ars Technica, and the company fixed it last month.

Google's was far worse: an 8.0 out of 10. Ars Technica reports the problem lived in Google's MCP toolbox for databases, an open-source project called googleapis/mcp-toolbox. Its HTTP client was initialized without a CheckRedirect policy, meaning it never properly controlled what happened when a URL redirected somewhere else, and it also failed to validate target IP addresses. That combination enabled server-side request forgery, where an attacker tricks a server into making network requests it was never supposed to make.

Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars Technica the design flaw is what makes this hard to catch. "Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work," McKee said. "Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between."

The list keeps growing

Mohiuddin published an update this month expanding on his findings, according to a report from The Next Web, aggregated by Ground News. That update names Google, JPMorgan Chase, Weaviate, France's DINUM, and the city government of Tangerang, Indonesia as organizations that fixed the same type of flaw. The updated list doesn't repeat Rapid7 or the US federal government from the original set Ars Technica reported, and instead adds Tangerang's city government. It isn't clear from either report whether that reflects a narrower follow-up disclosure or a separate batch of findings. Either way, the pattern is consistent. Public and private sector agent deployments with nothing in common except running MCP keep turning up the same hole.

A second, different MCP problem

This isn't the only MCP vulnerability that has emerged. Ground News also surfaced a separate finding from OX Security, which traced a different flaw to MCP's STDIO transport layer, a mechanism that lets a subprocess execute operating system commands without proper checks. OX Security says that issue could affect roughly 200,000 servers, and that Anthropic, which maintains MCP, called the behavior expected rather than treating it as something to patch. This is a distinct issue from the agent-to-agent trust chain Mohiuddin tested. If the protocol's own maintainer sees a wide-open subprocess execution path as working as intended, individual companies patching their own instances won't fix the underlying design.

Tech AI Magazine's write-up on this story stays vague, warning that "experts" flag MCP as a security risk without naming a single researcher, company, or vulnerability. That framing makes a specific, documented set of disclosures sound like a generic industry worry, when Mohiuddin's work and the CVE Rapid7 patched are concrete and attributable.

None of the organizations involved have described these incidents as breaches with confirmed data loss. Google, Rapid7, and the other named organizations fixed the specific bugs Mohiuddin reported to them. What none of them have done, based on the available reporting, is change how MCP itself handles trust between agents by default. Until the protocol's trust model changes, security researchers will likely keep finding the same category of flaw in the next large organization that builds an AI agent network on top of it.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaMCP for agent-to-agent comms may be the riskiest protocol you've never heard of
unknown
moyanai.appMCP for agent-to-agent comms may be the riskiest protocol you've never heard of
unknown
daily.devMCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of
unknown
Data World BankMCP for agent-to-agent comms may be the riskiest protocol you've never heard of - Technology data bank
unknown
Ground NewsGoogle, JPMorgan and Two Governments Fixed the Same MCP Flaw
unknown
Tech AI MagazineMCP Protocol Raises Concerns Over Agent-to-Agent Communication Risks - Tech AI Magazine - The World's Leading AI Magazine