Five Organizations, One Flaw: The Same MCP SSRF Bug Fixed at Google, JPMorgan and Two Governments
Posted on 6th Oct 2026 12:06:14 in Artificial Intelligence, Machine Learning
Tagged as: MCP, Model Context Protocol, SSRF, protocol pivoting, AI agent security, CVE-2026-14540, Google, JPMorgan, DINUM, cybersecurity
An independent security researcher's October update has turned a six-month-old prediction into a pattern that enterprises building on AI agents can no longer dismiss as coincidence. In May 2026, Syed Anas Mohiuddin published a preprint on Zenodo arguing that the trust assumptions baked into agentic AI protocols were structural — that the same class of vulnerability would inevitably surface in servers written by teams sharing no code, no industry, no country and no owner. On October 5, Ars Technica reported the results of his follow-up: the same server-side request forgery (SSRF) mistake in Model Context Protocol (MCP) servers has now been confirmed and fixed by security teams at five unrelated organizations — Google, JPMorgan Chase, Weaviate, France's interministerial digital directorate (DINUM) and the Tangerang City government in Indonesia.
The update, titled "Protocol Pivoting, four months later," matters well beyond the five codebases it documents. MCP is the standard AI agents use to call tools and data sources — the connective tissue between a model that decides and the systems that actually do. If its failure modes are structural rather than accidental, every business wiring agents into its payments, records or customer platforms inherits the same questions. The tally so far: five organizations that fixed the same SSRF class, two published CVEs, sixteen GitHub security advisories crediting Mohiuddin as reporter, and five findings in US federal MCP servers that remain open.
The Flaw, and Why It Keeps Coming Back
The mechanics fit in a few sentences, which is precisely the problem. An MCP server takes a URL, path or endpoint handed to it by an agent and builds an outbound request from it — without checking where that address actually resolves. Whoever steers the agent decides what the server's network identity talks to, including internal systems the outside world was never meant to reach. A second failure mode compounds it: MCP servers write full upstream API responses into centralized logs without redaction, something ordinary validation errors are enough to trigger.
Both behaviors trace to a single assumption — that data crossing the MCP boundary is trusted because it came from inside the system. In an agentic pipeline that assumption does not hold: a tool that sits "inside" the perimeter still acts on arguments shaped by an orchestrating model, and that model is routinely influenced by content it has just read. Trust that used to be implied by network position now has to be verified at every hop.
What gives the finding its weight is the sample. Google is a hyperscaler, JPMorgan a global bank, DINUM a national government, Tangerang a city administration and Weaviate a database vendor — five teams with nothing in common except the same defect. "Watching the same mistake come back from a hyperscaler, a bank, and a national government, one report at a time, is the moment the May argument stopped being a guess," Mohiuddin wrote.
Five Organizations, Five Fixes
The remediations, documented across advisories and pull requests, describe the same defensive pattern arriving from five directions:
- Google — CVE-2026-14540 covers an SSRF vulnerability in the generic HTTP source and tool components of mcp-toolbox versions 0.3.0 through 1.4.0. The National Vulnerability Database rates it 8.0, high severity: the HTTP client ran without a restrictive redirect policy and never validated destination IP addresses, so a crafted path parameter could push outbound requests toward internal or arbitrary external endpoints. Google merged the fix — pull request #3448 — on June 18, 2026, and shipped it in mcp-toolbox v1.5.0. The patch adds a guard against DNS-rebinding attacks, configurable allow and block lists for private networks and IP ranges, and validates the configured base URL at initialization rather than on first request.
- JPMorgan Chase — The bank's open-source jpmorgan-payments/ai repository includes a documentation-search MCP server whose read_documentation tool applied a domain allowlist before fetching, while its sibling related() tool fetched a caller-supplied URL server-side with no restriction. The component had been forked from an AWS project whose original never dereferenced the caller's URL. JPMorgan's Responsible Disclosure team confirmed the finding and deployed a fix; Mohiuddin now appears on the bank's public disclosure recognition page.
- Weaviate — The database vendor merged a pull request restricting its Google module's apiEndpoint, region and location settings to Google API hosts, and lists Mohiuddin in its public Security Hall of Fame.
- France's DINUM — datagouv-mcp, the official MCP server for France's national open-data platform, fetched a documentation URL supplied by any registered data.gouv.fr producer — a field that could point at loopback, private-network or cloud metadata addresses, with DNS rebinding able to swap the target between check and connect and a 302 redirect able to land on an internal host. The fix, pull request #126 titled "harden SSRF on external APIs," validates the destination IP at connect time, re-checks every redirect hop and refuses proxies.
- Tangerang City, Indonesia — The Wazuh-MCP-Server project shipped a tool whose advertised SSRF protection rejected only literal IP addresses and never resolved hostnames, so any DNS name pointing at a private, loopback or link-local address — including cloud instance metadata — bypassed it. A high-severity advisory published September 3, 2026 documents the fix.
From One Bug to Protocol Pivoting
The wider attack class Mohiuddin formalized in his May preprint is what he calls protocol pivoting: a multi-step attack in which an adversary enters through one protocol, exploits the trust assumptions that protocols place in each other, and escalates to capabilities available only through a different one. The paper presents three scenarios — MCP-to-A2A privilege escalation via implicit trust delegation, A2A-to-MCP capability injection through malicious agent impersonation, and cross-protocol prompt injection chains — and argues that existing defenses fail structurally against the class.
The concrete example is easy to picture. Text shaped like a task instruction for Google's A2A protocol is planted inside MCP tool output. An orchestrating agent passes it to a subagent as normal delegation; the subagent, trusting its orchestrator, runs it. Every piece in that chain did exactly what it was designed to do, which is what makes the pattern so hard to catch. Douglas McKee, Rapid7's director of vulnerability intelligence, told Ars Technica that this is precisely the difficulty, and Markus Vervier of X41 D-Sec framed the technique as a form of indirect prompt injection — the class of attacks that hides instructions inside content an agent is asked to process.
Conventional tooling struggles here by construction. Software composition analysis and dependency scanners stop at the transport boundary, because the dangerous input arrives over the wire as a tool argument described by a tool manifest the scanner never reads. Mohiuddin built mcp-safeguard, an open-source scanner that tests MCP servers through their exposed tool surface without source access, probing six classes: SSRF, excessive permissions, prompt-injection surfaces, information leakage, authentication gaps and lifecycle bypass. He is candid that pattern-matching tools, his own included, miss a large share of the class.
What Is Still Unfixed
The update is careful to separate confirmed fixes from open findings, and the open list is where the risk still sits. Five reports filed privately on September 2, covering MCP servers under the US General Services Administration's Technology Transformation Services, remain in triage: a Department of Veterans Affairs benefits-claims server, a CMS Blue Button server, a regulations.gov server, a USASpending server and a CDC PLACES server. In the Veterans Affairs case, the server logs the full upstream benefits-API error body at ERROR level without redaction. Those bodies can contain a veteran's name, Social Security number, date of birth and address, and routine validation failures are enough to trigger the logging during normal operation. Code-level detail is being withheld until the servers are patched.
A separate report about the Japan Digital Agency's jgrants-mcp-server, which had no authentication at all, also remains open — a pull request proposing an explicit opt-in before binding the server to anything other than loopback is awaiting review. In the confirmed column, one more published CVE rounds out the picture: CVE-2026-97228, a low-severity GraphQL query injection in Rapid7's Bulk Export MCP server, which the vendor fixed by parameterizing the export identifier and which also credits Mohiuddin as finder. Sixteen GitHub security advisories in total now carry his name, spanning SSRF as well as command injection, authentication gaps, session hijack, credential leaks and bypasses of earlier fixes, with patches merged in projects including github-mcp-server, mongodb-mcp-server and salesforce-mcp-server. Mohiuddin will present the cross-vendor pattern at MCPCon North America in San Jose on October 23.
What It Means for Teams Deploying AI Agents
Strip away the acronyms and the takeaways for businesses are concrete. First, treat every URL an agent can influence as attacker-controlled: the reference fixes resolve destinations at connection time, re-check each redirect hop, block private, loopback and link-local ranges — including the cloud metadata address 169.254.169.254 — and refuse proxies. Second, keep outbound allowlists narrow, the way Google and JPMorgan's fixed components now do: a fetch tool should reach the hosts it needs and nothing else. Third, redact upstream responses before they reach logs; the Veterans Affairs case shows that routine validation errors, not exotic exploits, are enough to leak names, identifiers and addresses. Fourth, inventory every MCP server you run the way you would inventory an internet-facing service — the pattern here was found by probing exposed tool surfaces, and the same lens works for defenders.
The bigger lesson is about trust architecture. MCP, Google's A2A protocol and emerging standards like the Agent Network Protocol were designed independently, each assuming it operates alone — and the moment agents orchestrate across them, every inherited assumption becomes a pivot point. For businesses moving quickly to put agents in front of customers, the practical question to put to any AI vendor is now the same one security teams at Google and JPMorgan had to answer: when your agent passes an argument to a tool, who verifies where that argument sends the request? Five organizations have answered that question in public. Several US federal servers have not — yet.
Sources
- Ars Technica — MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
- The Next Web — Google, JPMorgan and two governments fixed the same MCP flaw
- Unite.AI — Researcher Discloses Same MCP Flaw at Google, JPMorgan, Two Governments
- Zenodo (Syed Anas Mohiuddin) — Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems
- National Vulnerability Database — CVE-2026-14540 (Google mcp-toolbox SSRF)