SafetyRisk, alignment & guardrails
Same SSRF flaw found and fixed in MCP servers at Google, JPMorgan, Weaviate and two governments
An independent researcher found server-side request forgery bugs in Model Context Protocol servers run by Google, JPMorgan, Weaviate and two governments. The fixes confirm a recurring SSRF pattern, but claims of agent-to-agent 'protocol pivoting' attacks in production remain undemonstrated.

The confirmed flaws are a familiar web bug, server-side request forgery (SSRF), not a new kind of AI attack. Google's case is CVE-2026-14540, rated CVSS v4 8.0, in mcp-toolbox versions 0.3.0–1.4.0. Its HTTP client followed redirects and did not check target IP addresses, so crafted inputs could reach internal endpoints. Google fixed it in v1.5.0 with IP checks at connection time and settings to control which IP ranges are allowed. [1] [4] [5]
Reports say JPMorgan, Weaviate, France's DINUM and the Indonesian city of Tangerang fixed similar SSRF bugs. Fixes at those four organizations are reported by news outlets or the researcher, without separate vendor confirmation. A Rapid7 bug was a separate GraphQL injection rated 2.7, and five US federal servers were still in triage. [2] [6] [9]
The 'protocol pivoting' idea, in which attacks hop between MCP and Google's A2A agent protocol, comes from a conceptual preprint with no empirical evaluation. Experts quoted by Ars question the new label. Rapid7's Douglas McKee says the bugs underneath are long-known injection and SSRF with well-established fixes. X41 D-Sec's Markus Vervier calls the technique a subclass of indirect prompt injection that does not need the cross-protocol hop. [1] [3]
The defenses are well known. Treat URLs and parameters generated by a model as untrusted input. Check resolved IPs, enforce egress controls at the OS or container level, block private ranges, and do not follow redirects without checking them. Organizations running mcp-toolbox should upgrade to v1.5.0 or later. [1] [4] [8]
a vendor-confirmed fix and multiple reported fixes show MCP servers fetching URLs passed in by callers without network checks.
Read the full assessment
Implication: any organization running MCP tools may have the same exposure, whether or not multi-agent attack chains prove practical.
Executive brief
The confirmed bugs behind this story are mostly ordinary server-side request forgery (SSRF), not new kinds of AI attack. Independent researcher Syed Anas Mohiuddin found SSRF flaws in Model Context Protocol (MCP) servers at Google, JPMorgan Chase, Weaviate, France's digital directorate (DINUM) and an Indonesian city government, and all five fixed them (TNW). Ars Technica presents the findings as agent-to-agent "protocol pivoting" (Ars Technica). The public fixes show a repeated SSRF pattern. They do not, on their own, show multi-agent chains working in production. The lesson still holds: treat any input from a model as untrusted.
What changed and event timeline
Preprint names "protocol pivoting."
Mohiuddin's preprint describes three attack scenarios: MCP→A2A escalation, A2A→MCP injection and cross-protocol injection chains. The record lists no empirical evaluation.
Google ships an SSRF guard
Pull request #3448 adds an SSRFGuard and IP range controls to mcp-toolbox, credits Mohiuddin as reporter and ships in v1.5.0 the same day.
CVE-2026-14540 published
The record covers mcp-toolbox versions 0.3.0–1.4.0 and rates the flaw CVSS v4 8.0 (High), CWE-918.
More disclosures and fixes
Five US federal MCP servers were reported on September 2 and remain in triage. Tangerang published an advisory on September 3. The researcher reports Weaviate fixed its bug on September 7.
Ars frames the issue as structural
The article calls the pattern a structural flaw in MCP trust and quotes Rapid7 and X41 D-Sec researchers.
Capabilities and access
- Google MCP Toolbox for Databases: versions 0.3.0–1.4.0 are affected and v1.5.0 is fixed (OpenCVE).
- Rapid7 Bulk Export MCP server: CVE-2026-97228, rated 2.7. TNW describes it as GraphQL injection reachable only with operator access (TNW).
- JPMorgan: a documentation-search MCP server fetched URLs supplied by the caller (medium severity).
Read the full section
- Google MCP Toolbox for Databases: versions 0.3.0–1.4.0 are affected and v1.5.0 is fixed (OpenCVE).
- Rapid7 Bulk Export MCP server: CVE-2026-97228, rated 2.7. TNW describes it as GraphQL injection reachable only with operator access (TNW).
- JPMorgan: a documentation-search MCP server fetched URLs supplied by the caller (medium severity).
- Weaviate: fixed by limiting endpoints to Google API hosts.
- DINUM: a commit titled "harden SSRF" (TNW).
- Scanner: the researcher publishes an open-source tool, mcp-safeguard (GitHub).
Technical analysis for researchers and developers
- Root cause at Google: Go's default HTTP client follows redirects automatically.
- The fix: IP checks at connection time to block DNS-rebinding (TOCTOU) attacks;
allowPrivateNetworks,allowedIpRangesandcustomBlockedIpRangessettings. - The researcher's draft standard: an individual IETF draft lists six MCP weakness classes.
Read the full section
- Root cause at Google: Go's default HTTP client follows redirects automatically. With no CheckRedirect policy and no check on target IP addresses, a crafted path parameter could send requests to internal endpoints (Ars Technica).
- The fix: IP checks at connection time to block DNS-rebinding (TOCTOU) attacks;
allowPrivateNetworks,allowedIpRangesandcustomBlockedIpRangessettings; and rejection of an unsafe base URL at startup (PR #3448). - The researcher's draft standard: an individual IETF draft lists six MCP weakness classes. Its advice: check resolved IPs, enforce egress controls at the OS or container level, avoid following redirects, finish the initialize handshake before serving tool calls, and keep attributable logs (IETF draft).
- Evidence gap: the pivoting preprint is conceptual and lists no reproducible benchmark (Zenodo).
Claims and evidence
- Google SSRF, CVSS 8.0, fixed: confirmed by Google's own pull request and CVE record (PR, OpenCVE).
- Fixes at five organizations: reported by TNW (TNW) and Unite.AI (Unite.AI). Advisories other than Google's were not independently checked here.
- Pivoting succeeded across five organizations: this is Ars's framing (Ars Technica). No independent demonstration of cross-protocol chains in production was found.
Read the full section
- Google SSRF, CVSS 8.0, fixed: confirmed by Google's own pull request and CVE record (PR, OpenCVE). This is vendor evidence that the bug was real.
- Fixes at five organizations: reported by TNW (TNW) and Unite.AI (Unite.AI). Advisories other than Google's were not independently checked here.
- Pivoting succeeded across five organizations: this is Ars's framing (Ars Technica). No independent demonstration of cross-protocol chains in production was found.
- SSRF in Anthropic's and Microsoft's fetch servers: reported by the researcher only. Fix status is unconfirmed (DEV Community).
Context and prior work
- Typical agent stacks run MCP for tool access, Google's A2A protocol for delegating work between agents, and newer standards such as the Agent Network Protocol in parallel (Zenodo).
- Rapid7's Douglas McKee says the bugs underneath are "old friends" (injection and SSRF) whose fixes are about 20 years old.
- A separate analysis frames the Google case as a problem at the HTTP egress boundary of the MCP tool path (redreamality).
Read the full section
- Typical agent stacks run MCP for tool access, Google's A2A protocol for delegating work between agents, and newer standards such as the Agent Network Protocol in parallel (Zenodo).
- Rapid7's Douglas McKee says the bugs underneath are "old friends" (injection and SSRF) whose fixes are about 20 years old. He credits the new name with getting defenders and standards bodies to design for the problem (Ars Technica).
- A separate analysis frames the Google case as a problem at the HTTP egress boundary of the MCP tool path (redreamality).
Limitations, safety and contested findings
- The new label is disputed. Markus Vervier of X41 D-Sec calls the technique a simple subclass of indirect prompt injection.
- The sources disagree on which organizations count. Ars includes Rapid7 and the US federal government among the tested organizations.
- Severities vary widely, from 2.7 to 8.0.
Read the full section
- The new label is disputed. Markus Vervier of X41 D-Sec calls the technique a simple subclass of indirect prompt injection. In his view the cross-protocol hop is not required for the attack to work, though he agrees it is hard to mitigate (Ars Technica).
- The sources disagree on which organizations count. Ars includes Rapid7 and the US federal government among the tested organizations. TNW says the five fixes include Tangerang, that Rapid7's bug is a separate GraphQL injection, and that the federal servers are still in triage (TNW).
- Severities vary widely, from 2.7 to 8.0.
Business and practitioner implications
- Inventory every MCP server you run, including internal ones and ones bundled from vendors. Upgrade mcp-toolbox to v1.5.0 or later (PR).
- Treat URLs and parameters produced by a model as untrusted input from strangers, as McKee advises (Ars Technica).
- Add egress filtering, block private IP ranges and don't follow redirects without checking them (IETF draft).
Read the full section
- Inventory every MCP server you run, including internal ones and ones bundled from vendors. Upgrade mcp-toolbox to v1.5.0 or later (PR).
- Treat URLs and parameters produced by a model as untrusted input from strangers, as McKee advises (Ars Technica).
- Add egress filtering, block private IP ranges and don't follow redirects without checking them (IETF draft).
- Require authorization for each call between agents rather than trusting other internal agents implicitly (zero trust).
Sources
Read the full section
- Ars Technica: MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
- TNW: Google, JPMorgan and two governments fixed the same MCP flaw
- Unite.AI: Researcher Discloses Same MCP Flaw at Google, JPMorgan, Two Governments
- Zenodo: Protocol Pivoting preprint
- GitHub: googleapis/mcp-toolbox PR #3448
- OpenCVE: CVE-2026-14540
- IETF: draft-mohiuddin-mcp-security-considerations-00
- DEV Community: Four vendors, one bad assumption
- GitHub: mcp-safeguard
- redreamality: SSRF on the MCP Tool Path
The source trail.
Sources (10)
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Article text retrieved; extracted text may omit tables or interactive elements.
arstechnica.com