Close Menu
iM.NewsiM.News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    TikTok Launches AI Shopping Assistant and In-App Checkout

    October 6, 2026

    MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts

    October 6, 2026

    Samsung Art Store Adds 30 British Museum Works

    October 6, 2026
    Facebook X (Twitter) Instagram
    iM.NewsiM.News
    Subscribe
    • Home
    • Lifestyle

      Miu Miu Blends Sportswear and Tailoring at Paris Fashion Week

      October 4, 2026

      Gut Bacteria Linked to Faster Brain Aging in Healthy Adults

      October 4, 2026

      Celsius Recall: Vodka Seltzer Cans Misbranded as Energy Drinks

      July 31, 2025

      Bruce Willis’ Illness Made Him Unable To Speak, Read, or Walk

      July 22, 2025

      FDA Recalls Over 67,000 Cases of Power Stick Deodorant

      July 20, 2025
    • Relations

      US Pulls B-1 Bombers from UK Base After Terror Arrests

      October 5, 2026

      Debris Found From Missing Medical Plane Off Nantucket

      October 4, 2026

      Kim Jong Un’s Sister Rejects Diplomacy From South Korea’s New President

      July 28, 2025

      Thailand–Cambodia Border Conflict Escalates Today With Airstrikes and Civilian Casualties

      July 24, 2025

      Trump Faces Revolt Over Epstein Files as Administration Pushes Back

      July 13, 2025
    • Technology

      TikTok Launches AI Shopping Assistant and In-App Checkout

      October 6, 2026

      MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts

      October 6, 2026

      Samsung Art Store Adds 30 British Museum Works

      October 6, 2026

      OpenAI Adds Invisible Watermarks to EU ChatGPT Text

      October 6, 2026

      Matic Robot Vacuum Gets FCC Ban Waiver Amid US Manufacturing Push

      October 5, 2026
    • Travel & Tourism

      American Airlines Returns to JFK-Seattle Nonstop Route in 2027

      October 5, 2026

      Air Canada Launches A321XLR Flights to London From Ottawa and Halifax

      October 4, 2026

      Massive Russian Earthquake Triggers Tsunami Warning for California’s North Coast

      July 30, 2025

      Alaska Airlines Grounded Nationwide Due To IT Outage

      July 21, 2025

      Fire Destroyed Tomorrowland Main Stage Days Before Opening

      July 17, 2025
    • Get in Touch
    iM.NewsiM.News
    Home»Technology»MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts
    Technology

    MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts

    im.newsBy im.newsOctober 6, 2026No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Server rack in a data center representing MCP protocol vulnerability
    Photo: Indrajit Das / Wikimedia Commons, CC BY-SA 3.0
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Security researchers have identified a significant vulnerability in the Model Context Protocol (MCP), a standard used for communication between AI applications and agents within internal networks. The flaw allows attackers to exploit trust gaps between agents, enabling the spread of malicious prompts that can lead to data exfiltration and unauthorized server actions.

    The issue affects multiple major organizations, including Google, JP Morgan Chase, Rapid7, and government agencies in France and the United States. Independent researcher Syed Anas Mohiuddin demonstrated that the vulnerability, which he terms “protocol pivoting,” works by targeting specific agents rather than the large language model (LLM) itself. Once an agent is compromised, it passes harmful instructions to other agents that explicitly trust the source, bypassing standard security guardrails.

    PDC server room
    Photo: Esquilo / Wikimedia Commons, CC BY-SA 3.0

    Google and Rapid7 Vulnerabilities

    Google disclosed a vulnerability in its MCP toolbox for databases, rated with a severity score of 8 out of 10. The flaw stemmed from the HTTP client initialization lacking a CheckRedirect policy and failing to validate target IP addresses. This allowed crafted path parameters to redirect requests to internal endpoints, effectively enabling server-side request forgery (SSRF). Google addressed the issue by implementing an allow-list of IP ranges and block lists, rejecting unsafe base URLs at startup.

    Rapid7 also acknowledged a vulnerability in its network, assigned CVE-2026-97228. Although rated at a lower severity of 2.7, the flaw demonstrated the broader risk of the protocol. Rapid7 fixed the issue last month. Douglas McKee, director of vulnerability intelligence at Rapid7, noted that the attack chain relies on each protocol checking its own front door while ignoring the hallway between them.

    Trust Gaps in Agentic Networks

    The core of the problem lies in the design of agentic architectures. Many special-purpose agents lack the robust guardrails found in general-purpose LLMs. Because MCP servers store credentials for each agent, and agents are built to trust every other internal agent, an exploit that would be rejected by an LLM can succeed when passed between agents.

    Front Franklin Cray XT4 racks
    Photo: Unknown / Rawpixel, CC0

    Mohiuddin described the technique as a multi-step attack where an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities accessible only via a different protocol. This often involves delegating tasks through Google’s Agent-to-Agent (A2A) protocol or emerging standards like the Agent Network Protocol.

    Markus Vervier, a researcher at X41 D-Sec, argued that the term “indirect prompt injection” is more accurate. He stated that the fact the malicious prompt comes from a different protocol is unexpected but not strictly required for such attacks to work. The vulnerability highlights a departure from zero trust principles, where networks assume nodes may be infected and require authorization for sensitive transactions.

    CAT8 Ethernet Cable
    Photo: Raimond Spekking / Wikimedia Commons, CC BY-SA 4.0

    McKee emphasized that any data passed from an LLM to a tool should be treated as input from a stranger on the internet. The underlying bugs, such as injection and SSRF, are well-known, but the fixes have not kept pace with the rapid adoption of agentic systems. Naming the attack class is a critical step for defenders and standards bodies to design appropriate mitigations.

    Source: Ars Technica

    Agent Vulnerabilities AI Security cybersecurity MCP Protocol Prompt Injection Technology
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSamsung Art Store Adds 30 British Museum Works
    Next Article TikTok Launches AI Shopping Assistant and In-App Checkout
    im.news

    Related Posts

    TikTok Launches AI Shopping Assistant and In-App Checkout

    October 6, 2026

    Samsung Art Store Adds 30 British Museum Works

    October 6, 2026

    OpenAI Adds Invisible Watermarks to EU ChatGPT Text

    October 6, 2026
    Leave A Reply Cancel Reply

    Latest Posts

    TikTok Launches AI Shopping Assistant and In-App Checkout

    October 6, 20260 Views

    MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts

    October 6, 20260 Views

    Samsung Art Store Adds 30 British Museum Works

    October 6, 20260 Views

    OpenAI Adds Invisible Watermarks to EU ChatGPT Text

    October 6, 20260 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss

    Epstein List Phase 1: Full Flight Logs, Client List Released

    February 28, 2025 News Focus 236 Views

    In a stunning development that has sent shockwaves through political and entertainment circles, Attorney General…

    Microsoft Stock Joins Exclusive $4 Trillion Club After Blockbuster Cloud + AI Earnings

    July 31, 2025

    DOJ & FBI Find No Epstein Client List, Suicide Confirmed

    July 7, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    We provide the daily life news. You find latest trendy news at our portal, from entertainment to economy or politics.

    We're accepting new partnerships right now.

    Email Us: info@im.news

    Facebook X (Twitter) RSS
    Our Picks

    TikTok Launches AI Shopping Assistant and In-App Checkout

    October 6, 2026

    MCP Protocol Flaw Lets AI Agents Spread Malicious Prompts

    October 6, 2026

    Samsung Art Store Adds 30 British Museum Works

    October 6, 2026
    Most Popular

    Epstein List Phase 1: Full Flight Logs, Client List Released

    February 28, 2025236 Views

    Microsoft Stock Joins Exclusive $4 Trillion Club After Blockbuster Cloud + AI Earnings

    July 31, 2025154 Views

    DOJ & FBI Find No Epstein Client List, Suicide Confirmed

    July 7, 2025119 Views
    © 2026 I'm News. Designed by I'm News.
    • Home
    • Lifestyle
    • Relations
    • Travel & Tourism
    • Technology

    Type above and press Enter to search. Press Esc to cancel.