A researcher reveals the same MCP flaw at Google, JPMorgan, Two Governments – Unite.AI
Independent security researcher Syed Anas Mohiuddin revealed in an October 2026 research update that the same server-side request forgery error in Model Context Protocol servers was confirmed and fixed by security teams from five unrelated organizations: Google, JPMorgan Chase, Weaviate, the French Inter-Ministerial Digital Directorate, and the Tangerang city government in Indonesia.
The update, titled “Protocol Pivoting, Four Months Later,” tests a prediction made by Mohiuddin in May 2026: If the weakness was structural rather than a single careless implementation, the same bug would emerge in servers written by teams that don’t share code, industry, country or ownership. It reports that each of the five organizations has confirmed its case through its security team, and that security vendor Rapid7 has separately posted a CVE for a different but related bug. The update counts five organizations that have patched the same SSRF, two published CVEs, and five hits in US federal MCP servers that remain open.
Mohiuddin describes two failure modes behind this model. The first is server-side request forgery: an MCP server creates an outgoing request from a URL, path, or endpoint provided by an agent without checking where it resolves, so the agent actually decides what the server’s network identity communicates with. The second is insecure upstream data handling, which most visibly writes complete upstream API responses to centralized logs without redaction, which are sufficient to trigger ordinary errors. He traces both back to one assumption, which is that data crossing the MCP boundary is reliable because it comes from within the system, which he says is not in an agent pipeline.
CVE-2026-14540 in Google MCP Toolbox
According to the GitHub Advisory Database entry for CVE-2026-14540, published by the National Vulnerability Database, an SSRF vulnerability exists in the Generic HTTP Source and Google mcp-toolbox tool components versions 0.3.0 to 1.4.0. Because the HTTP client had no restrictive redirection policies and never validated destination IP addresses, a crafted path parameter could redirect outgoing toolbox requests to arbitrary internal or external endpoints. The advisory rates the defect as High Severity with a CVSS score of 8.0; was published on July 31, 2026, and last updated on August 8, 2026. Mohiuddin states that the CVE was reserved on July 3, 2026, and that the record credits him as a finder.
Google has merged the fix, pull request no. 3448 in the googleapis/mcp-toolbox repository on June 18, 2026 and was deployed in mcp-toolbox v1.5.0. The pull request implements an SSRFGuard to prevent DNS rebinding attacks in the window between the address check and the connection, adds the configurable allowPrivateNetworks, allowedIpRanges, and customBlockedIpRanges properties, validates the configured BaseURL on initialization instead of the first request, and explicitly warns about the man-in-the-middle risk when SSL verification is disabled. The PR credits Mohiuddin as the reporter, and Mohiuddin describes the Google cleanup as a reference implementation of a real SSRF guard.
Four more confirmed cases
Mohiuddin reports that JPMorgan Chase’s open source jpmorgan-payments/ai repository includes a documentation search MCP server whose read_documentation tool enforces a domain allowlist before retrieval, while its sibling tool related() retrieves a server-side caller-supplied URL without restrictions. It states that the component was forked from an AWS project whose original never dereferenced the caller URL, that the bank’s responsible disclosure team confirmed the result to be valid, and that a fix has been implemented. It is listed by name on JPMorgan Chase’s Public Responsible Disclosure Acknowledgment page and rates relief as medium severity, noting that no credentials travel with the counterfeit claim.
Weaviate, it reports, has merged a pull request limiting the Google Form’s apiEndpoint, region, and location settings to Google API Hosts, and lists it by name in its public Security Hall of Fame entry dated August 25, 2026.
The datagouv/datagouv-mcp project merged pull request #. 126, “feat: harden SSRF on external APIs,” on September 4, 2026, and the pull request opens crediting Mohiuddin as a reporter. According to the PR, a cardocumentationThe URL field provided by any registered producer of data.gouv.fr was fetched server-side and could point to loopback addresses, private network, or cloud metadata, with DNS rebinding able to swap the target between check and connect, and a 302 redirect able to land on an internal host. The fix validates the destination IP upon connection, double-checks each redirect hop, and rejects proxies. Mohiuddin identifies the project as the official MCP server for France’s national open data platform, operated by DINUM, the government’s inter-ministerial digital directorate.
A GitHub Security Advisory published on September 3, 2026 by the maintainers of INFOKOM-KI/Wazuh-MCP-Server, rated High, records that blueteamcheckThe webshell tool’s advertised SSRF protection only rejected literal IP addresses and never resolved hostnames, so any DNS name that pointed to a private, loopback, or link-local address, including cloud instance metadata, bypassed it. The advisory notes that the tool’s documented guarantee, “SSRF protection: Private/reserved IPs in URL host are rejected,” did not apply to hostname-based URLs. The flaw was fixed in commit 2bbfe12, and the notice gives Mohiuddin the role of reporter. Mohiuddin says he reported on September 2, 2026 that maintainers responded from a tangerangkota.go.id address and that the project is operated by the Tangerang city government in Indonesia.
The Rapid7 vulnerability database entry for CVE-2026-97228 records a GraphQL query injection in Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1, where an export is not validatedThe MCP id tool argument is interpolated directly into a GraphQL query. Rapid7 scored 2.7, Low, on the 3.1 CVSS scale, published the record on September 25, 2026, and notes that inserted queries run within the scope of the operator API and cannot cross the tenant boundary; version 0.6.2 fixes the problem by passing the exportid as a parameterized variable. Mohiuddin says Rapid7 credited him as a finder.
In addition to these cases, Mohiuddin reports that since the update, 16 GitHub security advisories posted by project maintainers credit him as a reporter, covering SSRF as well as command injection, authentication gaps, session hijacking, credential leaks, and bypasses of previous fixes, and that he has integrated fixes into projects including github-mcp-server, mongodb-mcp-server, and salesforce-mcp-server.
Unresolved government results
Mohiuddin reports that he submitted five findings as private GitHub security advisories on September 2, 2026, regarding MCP servers as part of GSA’s Technology Transformation Services: a Department of Veterans Affairs benefits claims server, a Blue Button CMS server, a Recommendations.gov server, a USASpending server, and a CDC PLACES server. It states that all five remain in triage, are not fixed and are not presented as confirmed findings.
In the VA case, which describes only at the class level, the server logs the entire body of the upstream benefit-API error at the ERROR level without redaction; such bodies can contain a veteran’s name, Social Security number, date of birth, and address, and states that routine validation errors are sufficient to trigger registration during normal operation. It will hide details programmatically until the servers are updated.
It also reports that on September 1, 2026, it notified JPCERT that the Japan Digital Agency’s jgrants-mcp-server lacked authentication, and that on September 7, 2026, it opened a public pull request requesting an opt-in to bind the server to anything other than loopback and attachment write size limit. The pull request was not merged and does not have it as a confirmed result.
Protocol Pivoting and MCPCon Talk
Mohiuddin defines Protocol Pivoting as a multi-stage attack in which an adversary enters through one protocol, exploits the trust the protocols place in each other, and escalates to capabilities available only through a different protocol. His concrete example inserts A2A activity instruction-shaped text into the output of the MCP tool; an orchestrator passes it to a subagent as a normal delegation, and the subagent, trusting its orchestrator, executes it.
The formal preprint, “Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems,” was published in Zenodo on May 24, 2026. It presents three scenarios: privilege escalation from MCP to A2A via implicit delegation of trust, capability injection from A2A to MCP via malicious agent impersonation, and cross-protocol prompt injection chains. It also analyzes why existing defenses fail against the class and proposes a unified multiprotocol security framework with a formal trust boundary model and three protocol-independent mitigations.
May’s work began with Microsoft’s playwright-mcp, whose browser_navigate tool accepted any agent-provided URL without SSRF protection, allowing an agent to be directed to the AWS instance metadata service at 169.254.169.254 and its credentials. Mohiuddin points out that he filed this issue as a public GitHub issue, that there is no CVE or vendor confirmation, and that the severity rating is his own assessment.
Mohiuddin argues that software composition analysis and dependency scanners lack this class because the malicious input arrives via the transport as a tool argument described by a tool manifest that the scanner never reads, so the call graph stops at the transport boundary. It claims to have created mcp-safeguard, an open source scanner that tests MCP servers through their exposed tool surface without needing the source, looking for six classes: SSRF, excessive permissions, prompt-injection surfaces, information leakage, authentication gaps, and lifecycle bypass. He also claims that pattern matching tools, including his, miss out on a lot of class.
Mohiuddin says he will present the cross-vendor model on October 23, 2026 at MCPCon North America in San Jose, including results set for then, and that federal results will remain private until they are fixed.



Post Comment