Cybersecurity
Researcher Discloses Same MCP Flaw at Google, JPMorgan, Two Governments

Independent security researcher Syed Anas Mohiuddin disclosed in an October 2026 research update that the same server-side request forgery mistake in Model Context Protocol servers has been confirmed and fixed by security teams at five unrelated organizations: Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate, and the Tangerang City government in Indonesia.
The update, titled “Protocol Pivoting, four months later,” tests a prediction Mohiuddin made in May 2026: if the weakness were structural rather than a single careless implementation, the same bug would surface in servers written by teams sharing no code, industry, country, or owner. He reports that each of the five organizations confirmed its case through its own security team, and that security vendor Rapid7 separately published a CVE for a different but related bug. The update tallies five organizations that fixed the same SSRF, two published CVEs, and five findings in US federal MCP servers that remain open.
Mohiuddin describes two failure modes behind the pattern. The first is server-side request forgery: an MCP server builds an outbound request from a URL, path, or endpoint supplied by an agent without checking where it resolves, so the agent effectively decides what the server’s network identity talks to. The second is unsafe handling of upstream data, most visibly writing full upstream API responses into centralized logs without redaction, which ordinary errors are enough to trigger. He traces both to one assumption, that data crossing the MCP boundary is trusted because it came from inside the system, which he argues does not hold in an agentic pipeline.
CVE-2026-14540 in Google’s MCP Toolbox
According to the GitHub Advisory Database entry for CVE-2026-14540, published by the National Vulnerability Database, an SSRF vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. Because the HTTP client had no restrictive redirect policy and never validated destination IP addresses, a crafted path parameter could redirect the toolbox’s outbound requests toward internal or arbitrary external endpoints. The advisory rates the flaw High severity with a CVSS score of 8.0; it was published July 31, 2026 and last updated August 8, 2026. Mohiuddin states the CVE was reserved on July 3, 2026 and that the record credits him as finder.
Google merged the fix, pull request #3448 in the googleapis/mcp-toolbox repository, on June 18, 2026, and it shipped in mcp-toolbox v1.5.0. The pull request implements an SSRFGuard to prevent DNS-rebinding attacks in the window between address check and connection, adds configurable allowPrivateNetworks, allowedIpRanges, and customBlockedIpRanges properties, validates the configured BaseURL at initialization rather than on first request, and warns explicitly about man-in-the-middle risk when SSL verification is disabled. The PR credits Mohiuddin as the reporter, and Mohiuddin describes Google’s remediation as a reference implementation of a real SSRF guard.
Four More Confirmed Cases
Mohiuddin reports that JPMorgan Chase’s open-source jpmorgan-payments/ai repository includes a documentation-search MCP server whose read_documentation tool applies a domain allowlist before fetching, while its sibling related() tool fetches a caller-supplied URL server-side with no restriction. He states the component was forked from an AWS project whose original never dereferenced the caller’s URL, that the bank’s Responsible Disclosure team confirmed the finding as valid, and that a fix has been deployed. He is listed by name on JPMorgan Chase’s public responsible-disclosure recognition page and rates the finding medium severity, noting that no credential travels with the forged request.
Weaviate, he reports, merged a pull request restricting the Google module’s apiEndpoint, region, and location settings to Google API hosts, and lists him by name in its public Security Hall of Fame entry dated August 25, 2026.
The datagouv/datagouv-mcp project merged pull request #126, “feat: harden SSRF on external APIs”, on September 4, 2026, and the pull request opens by crediting Mohiuddin as reporter. Per the PR, a machinedocumentationurl field supplied by any registered data.gouv.fr producer was fetched server-side and could point at loopback, private-network, or cloud metadata addresses, with DNS rebinding able to swap the target between check and connect and a 302 redirect able to land on an internal host. The fix validates the destination IP at connect time, re-checks every redirect hop, and refuses proxies. Mohiuddin identifies the project as the official MCP server for France’s national open-data platform, maintained by DINUM, the government’s interministerial digital directorate.
A GitHub Security Advisory published September 3, 2026 by the maintainers of INFOKOM-KI/Wazuh-MCP-Server, rated High, records that the blueteamcheckwebshell tool’s advertised SSRF protection rejected only literal IP addresses and never resolved hostnames, so any DNS name pointing at a private, loopback, or link-local address, including cloud instance metadata, bypassed it. The advisory notes the tool’s documented guarantee, “SSRF Protection: Private/reserved IPs in the URL host are rejected,” did not hold for hostname-based URLs. The flaw was patched in commit 2bbfe12, and the advisory credits Mohiuddin as reporter. Mohiuddin states he reported it on September 2, 2026, that maintainers responded from a tangerangkota.go.id address, and that the project is maintained by the Tangerang City government in Indonesia.
Rapid7’s vulnerability database entry for CVE-2026-97228 records a GraphQL query injection in Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1, in which an unvalidated exportid MCP tool argument is interpolated directly into a GraphQL query. Rapid7 scores it 2.7, Low, on the CVSS 3.1 scale, published the record September 25, 2026, and notes that injected queries execute within the operator’s own API scope and cannot cross a tenant boundary; version 0.6.2 fixes the issue by passing exportid as a parameterized variable. Mohiuddin states Rapid7 credited him as finder.
Beyond those cases, Mohiuddin reports that as of the update, 16 GitHub security advisories published by projects’ own maintainers credit him as reporter, covering SSRF as well as command injection, authentication gaps, session hijack, credential leaks, and bypasses of earlier fixes, and that he has had fixes merged in projects including github-mcp-server, mongodb-mcp-server, and salesforce-mcp-server.
Unresolved Government Findings
Mohiuddin reports filing five findings as private GitHub Security Advisories on September 2, 2026, covering MCP servers under the GSA’s Technology Transformation Services: a Department of Veterans Affairs benefits-claims server, a CMS Blue Button server, a regulations.gov server, a USASpending server, and a CDC PLACES server. He states all five remain in triage, are not fixed, and are not presented as confirmed outcomes.
In the VA case, which he describes only at the level of the class, the server logs the full upstream benefits-API error body at ERROR level without redaction; those bodies can contain a veteran’s name, Social Security number, date of birth, and address, and he states routine validation failures are enough to trigger the logging during normal operation. He is withholding code-level detail until the servers are patched.
He also reports that on September 1, 2026 he notified JPCERT that Japan Digital Agency’s jgrants-mcp-server had no authentication, and on September 7, 2026 he opened a public pull request requiring an explicit opt-in to bind the server to anything other than loopback and capping attachment write size. The pull request has not been merged, and he does not present it as a confirmed outcome.
Protocol Pivoting and the MCPCon Talk
Mohiuddin defines Protocol Pivoting as a multi-step attack in which an adversary enters through one protocol, exploits the trust assumptions protocols place in each other, and escalates to capabilities available only through a different one. His concrete example places text shaped like an A2A task instruction inside MCP tool output; an orchestrating agent passes it to a subagent as normal delegation, and the subagent, trusting its orchestrator, runs it.
The formal preprint, “Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems,” was published on Zenodo on May 24, 2026. It presents three scenarios: MCP-to-A2A privilege escalation via implicit trust delegation, A2A-to-MCP capability injection via malicious agent impersonation, and cross-protocol prompt injection chains. It also analyzes why existing defenses fail against the class and proposes a unified cross-protocol security framework with a formal trust boundary model and three protocol-agnostic mitigations.
The May work began with Microsoft’s playwright-mcp, whose browser_navigate tool accepted any URL the agent supplied with no SSRF protection, allowing an agent to be steered to the AWS instance metadata service at 169.254.169.254 and its credentials. Mohiuddin notes he filed this as a public GitHub issue, that there is no CVE and no vendor confirmation, and that the severity rating is his own assessment.
Mohiuddin argues that software composition analysis and dependency scanners miss this class because the dangerous input arrives over the transport as a tool argument described by a tool manifest the scanner never reads, so the call graph stops at the transport boundary. He states he built mcp-safeguard, an open-source scanner that tests MCP servers through their exposed tool surface without needing source, looking for six classes: SSRF, excessive permissions, prompt-injection surfaces, information leakage, authentication gaps, and lifecycle bypass. He also states that pattern-matching tools, his own included, miss a large share of the class.
Mohiuddin states he will present the cross-vendor pattern on October 23, 2026 at MCPCon North America in San Jose, including whichever findings are fixed by then, and that the federal findings will remain private until they are patched.












