The same MCP bug turned up at Google, JPMorgan and two governments. Treat every agent input like a stranger's
Your agents trust each other. That is exactly the gap attackers are using.
What happened
Ars Technica reports that in the past five months, Google and four other organizations have acknowledged vulnerabilities in which one AI agent inside a network spreads harmful instructions to other internal agents. Independent researcher Syed Anas Mohiuddin found the issues by testing agents built on MCP, the Model Context Protocol, from organizations including Google, JPMorgan Chase, Weaviate, Rapid7 and the French government's digital directorate.
The pattern: someone plants text in content, an agent reads it and hands it on as a normal delegated task, and the second agent runs it because it trusts the first. In many cases the result was server-side request forgery, where a server makes network requests on the attacker's behalf.
Google's bug, rated 8 out of 10, came from an MCP toolbox for databases whose HTTP client did not control redirects or validate target IP addresses. The fix added IP allow and block lists and rejects unsafe base URLs at startup. The researcher's own write-up describes a JPMorgan server where one fetch tool checked a domain allowlist and its sibling tool did not.
Rapid7's Douglas McKee summed it up: anything passed from an LLM to your tool should be treated like input from a stranger on the internet.
My take
Most small business agent builds I see are not multi-agent meshes, but they have the same shape. An agent reads an inbound email, a form or a web page, then calls a tool that touches the CRM, a webhook or an internal API.
My checklist when I wire agents into client systems:
- Every tool validates its own inputs. Do not rely on the calling agent to have filtered anything.
- URLs get an allowlist. If a tool fetches a URL, it only fetches domains you named in advance.
- Credentials stay scoped per tool. A summarizing agent does not need the key that writes to the CRM.
- Agent to agent handoffs are treated as untrusted input, with the same checks as a public form.
- Copied code gets re-reviewed. The JPMorgan case came from a fork that added a fetch and left out the check.
None of this is new security. It is old security applied to a new kind of caller.
More posts
- Google's EmbeddingGemma 2 runs search and RAG on device in about 191MB of RAM. Private client data can stay localOct 7, 2026
- Customers' AI agents are getting blocked by human checks and bot defenses. Your client's site may be turning buyers awayOct 7, 2026
- Siena raised $17M to give support, shopping and social agents one shared memory of each customer. Your CRM should do the sameOct 7, 2026
