Complete AI Training

AI news ·

Researcher finds trust flaw in MCP protocol used by Google, JP Morgan and other AI agents

A structural flaw in the Model Context Protocol lets a compromised AI agent relay malicious instructions to other agents inside trusted networks. Over five months, Google, JP Morgan Chase, and four other organizations confirmed vulnerabilities that could enable data exfiltration.

Share

A structural flaw in the Model Context Protocol (MCP) lets a compromised AI agent spread malicious instructions to other agents inside trusted internal networks. Independent researcher Syed Anas Mohiuddin demonstrated the attack against agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. Over five months, each organization acknowledged vulnerabilities that could enable data exfiltration or unauthorized server-side requests.

The technique exploits the default trust between agents that handle specialized tasks like translation or data analysis. Because many of these purpose-built agents run without strong guardrails, an attacker who compromises one can use it to relay harmful commands across the network. MCP servers store credentials that make this lateral movement straightforward inside environments already considered safe.

How the trust flaw works

MCP is designed as a standard for AI agents to communicate within internal systems. The protocol assumes that agents operating inside the same network are trustworthy. Mohiuddin's research shows that assumption breaks down when even a single agent is compromised. The attacker's agent can issue instructions that other agents follow without question, bypassing standard security checks.

The result is a form of server-side request forgery. A malicious actor can force agents to make network calls they should not make, pulling sensitive data from internal services or sending it to external locations. The attack does not need to break encryption or authentication - it simply uses the permissions the agents already have.

Organizations affected and response

The proof-of-concept attacks spanned financial services, cloud infrastructure, cybersecurity, and government systems. Google and JP Morgan Chase confirmed the vulnerability in their agent deployments, as did Weviate, Rapid7, the French interministerial digital directorate, and a US federal agency. Each organization has acknowledged the issue, though specific remediation timelines vary.

The core problem sits at the protocol level, not in any single implementation. Because MCP servers hold credentials that grant broad internal access, fixing the issue requires rethinking how agents authenticate each other rather than patching individual products.

The broader security gap in agent systems

Special-purpose AI agents are typically built for speed and narrow functionality. Security guardrails are often minimal, since the agents run inside networks already protected by perimeter defenses. Mohiuddin's work shows that perimeter security is not enough - once an attacker is inside, the agents themselves become a pathway to sensitive systems.

Professionals who work with AI Security Analytics Courses or manage agent deployments should treat inter-agent communication as a potential attack surface. The same applies to teams building on MCP-based architectures.

Why this matters for IT and development teams

If your organization deploys AI agents that communicate over MCP, assume that a compromised agent can reach anything its credentials allow. Audit the permissions granted to each agent and segment access so that a translation agent cannot query financial databases or HR systems. Treat agent-to-agent traffic with the same scrutiny applied to user-to-server requests.

Mohiuddin's work also signals that protocol-level security for AI systems is still immature. The organizations affected are not startups cutting corners - they are large enterprises and government bodies with dedicated security teams. The fact that the flaw persisted across all of them suggests that standard security reviews are not yet catching these agent-specific trust problems.

Share