MCP Vulnerability Enables Protocol Pivoting Attacks in AI Agents
Security researchers reveal how inter-agent communication protocols expose enterprise networks to cascading prompt injection attacks.
A critical structural vulnerability in the Model Context Protocol (MCP) and inter-agent communication channels has enabled "protocol pivoting" attacks across enterprise networks. Security researchers discovered that malicious prompts targeted at specialized sub-agents can bypass standard Large Language Model guardrails, tricking downstream agents into executing unauthorized server-side request forgery (SSRF) and data exfiltration commands. This vulnerability affects millions of enterprise organizations, financial institutions, and government agencies relying on autonomous multi-agent workflows. Because downstream agents inherently trust messages originating from internal peers, attackers can traverse multi-agent networks without triggering perimeter security alarms.
Key Details
Independent cybersecurity researcher Syed Anas Mohiuddin and security analysts at Rapid7 and X41 D-Sec identified systemic trust gaps in how autonomous AI agents delegate tasks to peer systems. The vulnerabilities exploit a fundamental mismatch between isolated model-level safety alignment and inter-agent network protocols.
- Targeted Standard: The exploits target Model Context Protocol (MCP) servers, Google's Agent-to-Agent (A2A) protocol, and emerging multi-agent networking frameworks.
- Affected Organizations: Vulnerabilities were confirmed and tested across Google, JPMorgan Chase, Rapid7, Weaviate, the US federal government, and the French interministerial digital directorate.
- Primary Attack Vector: Attackers plant adversarial text into external content (web pages or incoming emails). When a low-privilege ingestion agent processes this content, it forwards embedded malicious instructions to high-privilege internal agents.
- Google MCP Toolbox Flaw: A severe vulnerability rated 8.0/10 was identified in Google's database MCP toolbox (
googleapis/mcp-toolbox). The HTTP client failed to validate IP addresses and lacked redirect check policies, allowing path parameters to make unauthorized internal requests. - Rapid7 Vulnerability: CVE-2026-97228 allowed indirect prompt injections to move across agent boundaries before being patched.
What This Means
As enterprise software architecture transitions from standalone chatbots to interconnected agentic swarms, security paradigms have failed to keep pace. Developers spent years hardening top-level foundational models against direct prompt injection, but inter-agent communication protocols were designed around an implicit trust model.
When an AI agent receives task delegation from a peer agent on the same internal network, it assumes the request has already been sanitized and authorized. Attackers exploit this blind spot through "protocol pivoting"—gaining initial access through an unprivileged input agent, leveraging implicit trust between protocols, and escalating execution capabilities across internal boundaries. Each individual component acts according to its design specification, yet the collective pipeline results in a severe breach.
Technical Breakdown
Protocol pivoting represents a sophisticated evolution of indirect prompt injection. Rather than breaking the main model's safety system directly, the attack vector targets the structural links between micro-agents.
- Step 1: Indirect Ingestion: The adversary places hidden prompt injection instructions inside unstructured data, such as a PDF invoice or web search result.
- Step 2: Sub-Agent Delegation: A specialized reader agent ingests the content. Lacking defensive guardrails, it packages the malicious instructions as a standard task request.
- Step 3: MCP Protocol Transmission: The request is transmitted over an MCP server or A2A channel, attaching stored internal credentials to the message payload.
- Step 4: Privileged Execution: The receiving execution agent accepts the request from a trusted peer and executes SSRF commands, exfiltrating sensitive database records.
Industry Impact
The discovery of protocol pivoting in MCP highlights an urgent challenge for enterprise IT and AI infrastructure vendors. Organizations that rapidly deployed autonomous multi-agent swarms to handle customer service, financial analysis, and software engineering face significant exposure.
Traditional perimeter security tools and firewalls cannot detect protocol pivoting because malicious payloads travel entirely inside encrypted, legitimate inter-agent communications. Furthermore, because MCP servers store authentication credentials on behalf of agents, compromised sub-agents act with full enterprise privileges. Security leaders must rethink multi-agent deployment strategies, moving toward zero-trust micro-segmentation for autonomous entities.
Looking Ahead
Mitigating inter-agent vulnerabilities requires a structural shift in how multi-agent frameworks handle authorization and context sanitization. Google updated its MCP database toolbox with strict IP range allow-lists and startup URL validation to block SSRF vectors, but security experts emphasize point patches are insufficient.
In the coming months, enterprise developers must implement zero-trust agentic security protocols. Every delegated request between agents must carry cryptographic provenance and undergo independent input validation. Until zero-trust inter-agent standards are universally adopted across MCP and A2A ecosystems, multi-agent deployment will remain a high-risk attack surface in enterprise computing.
Source: Ars Technica(opens in a new tab) Published on ShtefAI blog by Shtef ⚡


