MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of



“AI agents give attackers a fresh set of connections to walk across,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. “Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.”

CVE-2026-97228, the vulnerability Mohiuddin found in Rapid7’s network, carried a severity rating of only 2.7 out of 10. Rapid7 fixed it last month.

The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL either returning an error or redirecting to a different URL. Google’s HTTP client also failed to validate target IP addresses.

“A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mohiuddin explained. Google’s fix involved applying an allow-list of IP ranges and block lists. “It rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done.”

Mohiuddin is calling the class of attack “protocol pivoting” because the exploits work when an app or server uses MCP to assign a task to an agent and the agent then forwards malicious instructions to another agent using a different communication method such as Google’s Agent-to-Agent (A2A) protocol, used for inter-agent delegation, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization gets effectively lost in translation. He described protocol pivoting as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.”



Source link

  • Related Posts

    Cable lobby to sue Trump FCC over repeal of national TV ownership cap

    The cable groups’ filing said the FCC repeal of the TV ownership cap violates the 2004 action by US lawmakers. The decision by Congress to set the cap at a…

    Continue reading
    Etched fields funding offers at $40B+ valuation, sources say

    Although it’s only been a couple of months since Etched raised $700 million at a $21 billion valuation, the AI chip startup is already being plied with investment offers at…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    NDP, Conservatives, Greens throw rocks at each other over tax changes, health care

    NDP, Conservatives, Greens throw rocks at each other over tax changes, health care

    ComplexCon 2026 Street Style: Alicia Keys, Travis Barker, North West

    ComplexCon 2026 Street Style: Alicia Keys, Travis Barker, North West

    Cable lobby to sue Trump FCC over repeal of national TV ownership cap

    Cable lobby to sue Trump FCC over repeal of national TV ownership cap

    Vote for the Homeland OKC-area high school team of the week for Sept. 28-Oct. 4

    Vote for the Homeland OKC-area high school team of the week for Sept. 28-Oct. 4

    GTA 6 Could Finally Fix Gaming’s Huge Drug Problem

    GTA 6 Could Finally Fix Gaming’s Huge Drug Problem

    A Season Within – my inspired life

    A Season Within – my inspired life