Five Agent Vulnerabilities in Five Months Expose Structural Flaw in MCP
Google and four other organizations acknowledged agent vulnerabilities in five months. Researcher Syed Anas Mohiuddin exploits MCP trust gaps to chain malicious instructions between agents.
Updated
Why it matters
- Google and four other organizations acknowledged agent vulnerabilities in the past five months.
- Researcher Syed Anas Mohiuddin tested agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government.
- The attacks exploit trust gaps in MCP, the Model Context Protocol, used for agent-to-agent communication inside internal networks.
- The technique is a specialized prompt injection targeting agents — not the LLM — and can exfiltrate database contents and sensitive business and personal information.
Google and four other organizations have acknowledged vulnerabilities in their AI agents over the past five months — all exploiting the same structural weakness: one compromised agent instructing other agents inside the same network to carry out malicious actions.
Independent researcher Syed Anas Mohiuddin demonstrated the attacks in proof-of-concept exploits against agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. The technique exfiltrates database contents and sensitive business and personal information by abusing trust relationships between agents that communicate over MCP, the Model Context Protocol.
The finding lands as AI agents spread into millions of organizations, giving attackers a new class of targets that conventional security controls were not designed to protect.
What makes this attack different from ordinary prompt injection?
The technique is a specialized form of prompt injection. But it does not target the underlying large language model. It targets a specific agent — for example, one built for translation or data analysis.
The attack chain works because of how agents treat each other:
- An attacker compromises or manipulates one agent inside a targeted network.
- That agent passes harmful instructions down the chain to other internal agents.
- Guardrails inside the first agent, if they exist at all, are often lax and fail to block the instructions.
- The downstream agent explicitly trusts the first agent — and follows its directions.
That final step is the core of the problem. A malicious instruction arriving from an external source can be filtered, flagged, or refused. The same instruction arriving from a trusted internal agent gets executed. The trust that makes multi-agent systems efficient also makes them a propagation path.
What is MCP, and why does the flaw sit in the protocol?
MCP, short for Model Context Protocol, is a standard for how AI applications and agents communicate with each other inside an internal network. It is one of the mechanisms that lets an agent built for one task hand off work, data, or instructions to an agent built for another.
Mohiuddin's proof-of-concept attacks exploit trust gaps in this protocol-level communication. The significance is that the weakness is not a bug in a single vendor's implementation that a patch can fix. The acknowledged vulnerabilities span Google and four other organizations that, as reported, have little in common except their use of AI agents. The common denominator is the pattern of inter-agent trust itself.
That is why the flaw is described as unexpected and hard to mitigate. Patching one agent closes one door. The structural exposure remains as long as agents on a network automatically trust instructions that originate from other agents on the same network.
Who has been tested, and what was demonstrated?
Mohiuddin tested agents from a range of high-profile organizations:
- JP Morgan Chase
- Weviate
- Rapid7
- The French government's interministerial digital directorate
- The US federal government
The targets span consumer tech, banking, security tooling, and government — an indication that the exposure is not confined to one sector or one deployment model. Over the past five months, Google and four other organizations have acknowledged vulnerabilities fitting this pattern, according to the report.
The demonstrated impact is concrete: the attacks can make agents take malicious actions, including exfiltrating database contents and sensitive business and personal information.
Why does this matter now?
The adoption of AI agents in millions of organizations is creating new opportunities for attackers, and this research shows one of the ways those opportunities materialize in practice. The stakes are both operational and architectural.
On the operational side, agents increasingly hold credentials, query databases, and move data between systems. An attack that co-opts an agent inherits all of those capabilities. Exfiltration stops being a network intrusion problem and becomes a workflow problem — the agent performs the transfer as part of what looks like normal activity.
On the architectural side, the finding puts pressure on MCP and inter-agent communication standards generally. If trust between agents is granted implicitly by position on the network rather than verified per instruction, then every added agent widens the attack surface for every other agent. The report characterizes the resulting exposure as a structural flaw in MCP, and the breadth of affected organizations supports that reading: five acknowledged vulnerabilities in five months, across unrelated institutions.
For security teams, the immediate implication is to treat inter-agent channels as untrusted until proven otherwise — to inspect instructions passed between agents with the same scrutiny applied to instructions from users or external inputs. For standards bodies and vendors, the longer-term question is whether MCP-style protocols can add per-instruction verification without losing the low-friction interoperability that made them attractive in the first place.
Mohiuddin's research, and the string of acknowledgments from Google and the other affected organizations, suggest the industry will have to answer that question as agent deployments keep growing.
Original: modelcontextprotocol.io
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
200 articles