Google and Rapid7 patches reveal Model Context Protocol flaws
Protocol Pivoting Vulnerability in Model Context Protocol Agent Networks
“AI agents give attackers a fresh set of connections to walk across,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars regarding a newly understood class of cross-agent security flaws.
As enterprise adoption of autonomous AI agents scales across millions of organizations, security researchers have uncovered trust gaps in Model Context Protocol (MCP) implementations. In the past five months, Google and four other organizations acknowledged vulnerabilities that allow an attacker to compromise a single internal agent and propagate malicious instructions to other downstream systems. Independent researcher Syed Anas Mohiuddin demonstrated that because secondary agents explicitly trust commands delegated by primary agents within an internal network, guardrails fail to catch instructions that exfiltrate sensitive database contents and corporate data.
The Tech TL;DR:

- Model Context Protocol (MCP) enables internal AI agents to communicate and delegate tasks, creating an unmonitored lateral attack surface between isolated systems.
- Independent researcher Syed Anas Mohiuddin identified vulnerabilities across multiple implementations, coining the term “protocol pivoting” for multi-step exploits.
- Google patched an 8-rated vulnerability in its database MCP toolbox (CVE-related SSRF vector), while Rapid7 resolved CVE-2026-97228.
How Protocol Pivoting Exploits Agent-to-Agent Trust Assumptions
The core architectural vulnerability stems from how modern AI frameworks handle inter-agent delegation. According to technical findings analyzed by Ars, applications use MCP as a communication standard inside internal enterprise networks. When an adversary plants malicious text strings into standard input data, the first receiving agent reads the prompt and passes it along as a normal delegated task. Because downstream agents are designed to trust tasks handed to them by peer agents, the instructions execute without standard validation.
Douglas McKee of Rapid7 highlighted the invisible nature of these pathways: “Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.”
Google Patches Database Toolbox Vulnerability to Block Unauthorized Requests
The severity of these implementation flaws varies significantly across tech stacks. Google addressed an 8-rated vulnerability originating in its database MCP toolbox (`googleapis/mcp-toolbox`). The component initialized its HTTP client without a CheckRedirect policy or proper target IP address validation. Syed Anas Mohiuddin explained that a crafted path parameter allowed the toolbox to follow a redirect to an internal endpoint and transmit unauthorized requests on behalf of the attacker.
Google countered the flaw by implementing an allow-list of IP ranges and explicit block lists that reject unsafe base URLs at startup rather than on the initial request. Meanwhile, Rapid7 encountered and patched CVE-2026-97228 within its own network infrastructure, which carried a severity rating of 2.7 out of 10. Mohiuddin categorized these exploits as “protocol pivoting”—a multi-step attack vector where an adversary gains initial access via one protocol and subsequently escalates privileges by forwarding malicious instructions to other standards, such as Google’s Agent-to-Agent (A2A) protocol or the emerging Agent Network Protocol.
Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only. Always consult with certified IT and cybersecurity professionals before altering enterprise networks or handling sensitive data.