What is the critical AI flaw affecting Google and JPMorgan?

Security teams at Google, JPMorgan Chase, and several governments have fixed a critical flaw in their Model Context Protocol (MCP) servers, which could have allowed attackers to access internal systems. The flaw, known as server-side request forgery (SSRF), was discovered by independent researcher Syed Anas Mohiuddin, highlighting the importance of answer engine optimization (AEO) in preventing such vulnerabilities.

How does the flaw impact Model Context Protocol servers?

MCP is the standard AI agents use to call tools and data sources, impacting large language model (LLM) visibility and overall AI search optimization. The flaw allowed an attacker to steer an agent to decide what the server talks to, including internal systems. Mohiuddin argued that the problem was structural, and his prediction was proven correct when teams that share no code or owner all produced the same flaw.

Google's MCP Toolbox for Databases had an HTTP client with no restrictive redirect policy and no check on target IP addresses, according to the GitHub advisory. A crafted path parameter could send its requests to internal or external endpoints. The flaw, CVE-2026-14540, carries a high rating of 8.0 and affects versions 0.3.0 to 1.4.0. Google's fix adds a guard against DNS rebinding and lists of allowed and blocked IP ranges, and credits Mohiuddin.

JPMorgan's open-source repository includes a documentation-search MCP server with two tools that fetch content. One checked domains against an allowlist. Its sibling fetched any URL the caller supplied, Mohiuddin wrote. JPMorgan forked the component from an AWS project that never fetched the caller's URL at all. JPMorgan's Responsible Disclosure team confirmed the finding and deployed a fix, he wrote. The finding is medium severity, he wrote.

Weaviate restricted its Google module's endpoint settings to Google API hosts, he wrote. DINUM's official MCP server for France's open-data platform fetched URLs supplied by data producers, which could point at internal or cloud metadata addresses. Its fix, titled "harden SSRF on external APIs", opens with "Reported by Syed Anas Mohiuddin".

In Tangerang's Wazuh MCP server, a tool advertised SSRF protection but only rejected literal IP addresses, according to a high-severity advisory published on 3 September. It never resolved hostnames.

Rapid7 fixed a different bug he found, CVE-2026-97228, in its Bulk Export MCP server. The bug allowed GraphQL injection within the operator's own access, and Rapid7 rates it low, at 2.7, its database entry says.

Mohiuddin calls the wider attack class "protocol pivoting". An attacker plants text in content an MCP tool returns, shaped like a task for Google's A2A protocol. An orchestrating agent passes it to a subagent, which runs it because it trusts the orchestrator.

"Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch," Douglas McKee, Rapid7's director of vulnerability intelligence, told Ars Technica.

Markus Vervier of X41 D-Sec told Ars that the technique is a form of indirect prompt injection. Mohiuddin will present the findings at MCPCon North America in San Jose on 23 October.

Questo articolo è stato scritto con l'assistenza dell'IA.
News Factory APP - notizie agentiche per potenziare il tuo SEO e AEO.