Skip to content
by InfinyAI ES

IA en un minutoNewsSecurity

Security

A researcher finds the same security flaw in AI agents from Google, JPMorgan and the French government

By

In 30 seconds

Researcher Syed Anas Mohiuddin has found the same kind of flaw in MCP servers run by Google, JPMorgan Chase, Weaviate, the French government's DINUM and the city government of Tangerang. One agent reads a hidden instruction, passes it to another as a normal task, and the second carries it out because it trusts the first. Each organization confirmed the flaw and has fixed it.

Independent researcher Syed Anas Mohiuddin has found the same kind of flaw in MCP servers run by organizations that have nothing in common: Google, the bank JPMorgan Chase, the database company Weaviate, the French government's interministerial digital directorate (DINUM) and the city government of Tangerang, in Indonesia. MCP (Model Context Protocol) is the open standard that AI agents use to connect to tools and data, and MCP servers are the connectors that give them those tools. Ars Technica reported the findings.

The problem is trust. One agent reads content with a hidden instruction, passes it to another agent as a normal task, and the second agent carries it out because it trusts the first one. In many cases, the result is a server making requests to the internal network on the attacker's behalf. Mohiuddin calls it "protocol pivoting"; Markus Vervier, of the security firm X41 D-Sec, sees it as a form of indirect prompt injection.

Each organization confirmed the flaw and has fixed it. Google's, in its MCP toolbox for databases, was rated 8 out of 10 for severity (CVE-2026-14540). The cybersecurity company Rapid7 published another related flaw, rated low. Mohiuddin has also reported issues in five MCP servers built for the US federal government, which are still under review and which he does not present as confirmed.

Douglas McKee, of Rapid7, summed it up for Ars Technica: "anything passed from an LLM to your tool should be treated like input from a stranger on the internet."

Why it matters

MCP is the standard AI agents use to connect to tools and data, so this is a design flaw, not one company's bug.

Official source: Ars Technica

Is your website up to scratch? We will audit it for free

AI in your inbox, every day or every Friday

The stories that matter, each one in a minute. With the official source for every one.

Choose one or both:

You will get an email to confirm your subscription: until you click its link, you will not receive anything. You can unsubscribe from any email.