AI Agent Communication Protocol MCP Faces Critical Security Flaws

Image: Ars Technica · Source
Security researcher uncovers vulnerabilities in Model Context Protocol (MCP), widely used for AI agent-to-agent communication, enabling malicious prompts to spread and escalate within networks.
The Model Context Protocol (MCP), a new standard facilitating communication between AI agents within internal networks, has been found to contain significant security vulnerabilities that threaten enterprise AI deployments worldwide. Independent researcher Syed Anas Mohiuddin recently demonstrated a series of attacks exploiting trust gaps inherent in MCP, allowing malicious instructions to propagate between AI agents inside organizations.
These attacks represent a specialized form of prompt injection targeting not the underlying large language models (LLMs) but individual agents dedicated to specific functions such as translation or data analysis. Many such agents lack adequate internal safeguards, permitting harmful commands from one compromised agent to be trusted and executed by others downstream. The problem is compounded by MCP servers storing credentials that implicitly trust peer agents, allowing attackers to leverage this trust to execute unauthorized actions.
Mohiuddin tested affected agents from prominent organizations including Google, JP Morgan Chase, Rapid7, the French government, and others, revealing that the exploit technique—dubbed “protocol pivoting”—enables an adversary to gain initial access through one communication protocol and escalate permissions by exploiting assumptions of trust across different protocols. For example, an attacker might leverage MCP to assign a malicious task to an agent, which then forwards harmful commands via alternate protocols like Google’s Agent-to-Agent (A2A) protocol or emerging standards such as the Agent Network Protocol.
Notably, vulnerabilities identified included a flaw in Google’s MCP toolbox for databases, which lacked robust redirect validation policies, allowing attackers to induce server-side request forgery (SSRF) attacks. Google mitigated this by implementing strict IP allow-listing and rejecting unsafe base URLs at startup. Rapid7 addressed a related MCP vulnerability with a low severity score but took prompt corrective action.
Experts emphasize that the challenges arise because MCP and related protocols were designed assuming isolated operation without comprehensive cross-protocol trust checks. Douglas McKee of Rapid7 highlighted that "each protocol checks its own front door while nobody watches the hallway in between," underscoring architectural blind spots.
While some researchers classify these exploits as a subclass of prompt injection—indirect prompt injection—due to the malicious inputs crossing protocol boundaries, the broad applicability of the pivoting technique across diverse organizations points to systemic issues in current AI agent networks.
The core lesson for developers and system architects is the necessity of adopting zero-trust principles within AI agent ecosystems. Inputs passed from LLMs or other agents should be treated with the same suspicion as untrusted internet data, with rigorous validation and authorization steps. Established mitigations against injection and SSRF vulnerabilities remain relevant and should be integrated into modern AI workflows.
As AI agent adoption accelerates, uncovering and addressing these security gaps in MCP and related protocols is critical to safeguarding sensitive data and maintaining trust in automated systems.



Sources and original reporting
Read the original source ↗

Comments (0)
No comments yet. Start the discussion.
Write a comment
Comments are published after moderation. Your name and comment will be visible publicly. Account