AI Agent Vulnerability Exposes Structural Flaw in Multi-Protocol Framework
A newly discovered vulnerability in AI agents from Google and other companies has exposed a structural flaw in the Multi-Protocol (MCP) framework, according to cybersecurity experts. Douglas McKee, director of vulnerability intelligence at Rapid7, explained that AI agents can inadvertently pass malicious instructions between each other due to trust assumptions between different communication protocols. Each agent in the chain operates as designed, making the flaw difficult to detect.
The issue stems from the way tasks are delegated between agents using protocols like Google’s Agent-to-Agent (A2A) or emerging standards such as the Agent Network Protocol. Mohiuddin, who identified the vulnerability, described the attack method as protocol pivoting, where an adversary exploits trust assumptions between protocols to escalate privileges.
One of the vulnerabilities, CVE-2026-97228, found in Rapid7’s network, had a low severity rating of 2.7 out of 10 and was fixed last month. However, the flaw affecting Google was more severe, rated 8 out of 10. The vulnerability arose because Google’s MCP toolbox for databases (googleapis/mcp-toolbox) failed to initialize its HTTP client with a CheckRedirect policy, which controls how a server handles URL errors or redirects. Additionally, the toolbox did not validate target IP addresses, allowing a crafted path parameter to redirect requests to an internal endpoint.
Google’s fix involved applying an allow-list of IP ranges and block lists, rejecting unsafe base URLs at startup rather than on the first request. Mohiuddin emphasized that this approach is what a real SSRF guard should look like, noting that many MCP servers have not implemented such safeguards.