A researcher finds the same security flaw in AI agents from Google, JPMorgan and the French government

In 30 seconds
Researcher Syed Anas Mohiuddin has found the same kind of flaw in MCP servers run by Google, JPMorgan Chase, Weaviate, the French government's DINUM and the city government of Tangerang. One agent reads a hidden instruction, passes it to another as a normal task, and the second carries it out because it trusts the first. Each organization confirmed the flaw and has fixed it.
Independent researcher Syed Anas Mohiuddin has found the same kind of flaw in MCP servers run by organizations that have nothing in common: Google, the bank JPMorgan Chase, the database company Weaviate, the French government's interministerial digital directorate (DINUM) and the city government of Tangerang, in Indonesia. MCP (Model Context Protocol) is the open standard that AI agents use to connect to tools and data, and MCP servers are the connectors that give them those tools. Ars Technica reported the findings.
The problem is trust. One agent reads content with a hidden instruction, passes it to another agent as a normal task, and the second agent carries it out because it trusts the first one. In many cases, the result is a server making requests to the internal network on the attacker's behalf. Mohiuddin calls it "protocol pivoting"; Markus Vervier, of the security firm X41 D-Sec, sees it as a form of indirect prompt injection.
Each organization confirmed the flaw and has fixed it. Google's, in its MCP toolbox for databases, was rated 8 out of 10 for severity (CVE-2026-14540). The cybersecurity company Rapid7 published another related flaw, rated low. Mohiuddin has also reported issues in five MCP servers built for the US federal government, which are still under review and which he does not present as confirmed.
Douglas McKee, of Rapid7, summed it up for Ars Technica: "anything passed from an LLM to your tool should be treated like input from a stranger on the internet."
Why it matters
MCP is the standard AI agents use to connect to tools and data, so this is a design flaw, not one company's bug.
Official source: Ars Technica


