MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of



“AI agents give attackers a fresh set of connections to walk across,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. “Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.”

CVE-2026-97228, the vulnerability Mohiuddin found in Rapid7’s network, carried a severity rating of only 2.7 out of 10. Rapid7 fixed it last month.

The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL either returning an error or redirecting to a different URL. Google’s HTTP client also failed to validate target IP addresses.

“A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mohiuddin explained. Google’s fix involved applying an allow-list of IP ranges and block lists. “It rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done.”

Mohiuddin is calling the class of attack “protocol pivoting” because the exploits work when an app or server uses MCP to assign a task to an agent and the agent then forwards malicious instructions to another agent using a different communication method such as Google’s Agent-to-Agent (A2A) protocol, used for inter-agent delegation, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization gets effectively lost in translation. He described protocol pivoting as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.”



Source link

  • Related Posts

    Gemini Call for Me might tell your mom you’re running late

    Google may be expanding its “Call for Me” AI feature beyond business calls so you can use it to send messages to friends and family. Android Authority reports finding a…

    Continue reading
    Lucid Motors’ EV output falls to lowest level in almost two years

    Lucid Motors built 2,954 electric vehicles (EVs) in the third quarter of this year, a 54% drop from a year ago, as the company purposely limits production to better meet…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    The best cards to use for Target purchases

    The best cards to use for Target purchases

    Nebraska HC Matt Rhule makes cameo in HBO’s ‘Lanterns’ season finale

    Nebraska HC Matt Rhule makes cameo in HBO’s ‘Lanterns’ season finale

    Former B.C. Lion sued for allegedly injuring neighbour

    Former B.C. Lion sued for allegedly injuring neighbour

    Gemini Call for Me might tell your mom you’re running late

    Gemini Call for Me might tell your mom you’re running late

    Brandon Sanderson Books Are Buy 2, Get 1 Free Today

    Brandon Sanderson Books Are Buy 2, Get 1 Free Today

    Supreme Court wrestles with energy companies’ bid to block major climate-change lawsuit

    Supreme Court wrestles with energy companies’ bid to block major climate-change lawsuit