MCP Server Flaw Found in Google, JPMorgan, Governments, Some Fixes Applied
Independent security researcher Syed Anas Mohiuddin has uncovered a significant vulnerability in Model Context Protocol (MCP) servers, affecting major organizations like Google, JPMorgan Chase, and two government entities. In an October 2026 update, Mohiuddin revealed that the same server-side request forgery (SSRF) flaw was identified and patched by Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate, and the Tangerang City government in Indonesia. The findings confirmed his earlier prediction that the issue was structural rather than a result of isolated implementation errors.
The vulnerability allowed an MCP server to build outbound requests from user-supplied URLs without proper validation, effectively letting the user decide the server’s network interactions. Additionally, the flaw involved unsafe handling of upstream data, such as logging full API responses without redaction. Mohiuddin traced these issues to a misplaced assumption that data within the system was inherently trusted.
Google addressed the flaw, rated High severity with a CVSS score of 8.0, in its MCP Toolbox versions 0.3.0 through 1.4.0. The fix, implemented in version 1.5.0, included an SSRFGuard to prevent DNS-rebinding attacks and added properties to validate network destinations. JPMorgan Chase also confirmed and fixed a related issue in its open-source payments repository, while Weaviate and the French government’s open-data platform applied similar patches.
The Tangerang City government in Indonesia fixed a flaw in its INFOKOM-KI/Wazuh-MCP-Server, where the SSRF protection failed to resolve hostnames properly. Rapid7 also published a CVE for a different but related bug in its Bulk Export MCP. Despite these fixes, Mohiuddin reported that five MCP servers within U.S. federal agencies, including the Department of Veterans Affairs and the CDC, remain vulnerable, with no patches applied as of his latest update.