Skip to content
Back to Guavy Wire
Stocks

MCP Server Flaw Found in Google, JPMorgan, Governments, Some Fixes Applied

Instruments
GOOGL JPM
Share

Independent security researcher Syed Anas Mohiuddin has uncovered a significant vulnerability in Model Context Protocol (MCP) servers, affecting major organizations like Google, JPMorgan Chase, and two government entities. In an October 2026 update, Mohiuddin revealed that the same server-side request forgery (SSRF) flaw was identified and patched by Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate, and the Tangerang City government in Indonesia. The findings confirmed his earlier prediction that the issue was structural rather than a result of isolated implementation errors.

The vulnerability allowed an MCP server to build outbound requests from user-supplied URLs without proper validation, effectively letting the user decide the server’s network interactions. Additionally, the flaw involved unsafe handling of upstream data, such as logging full API responses without redaction. Mohiuddin traced these issues to a misplaced assumption that data within the system was inherently trusted.

Google addressed the flaw, rated High severity with a CVSS score of 8.0, in its MCP Toolbox versions 0.3.0 through 1.4.0. The fix, implemented in version 1.5.0, included an SSRFGuard to prevent DNS-rebinding attacks and added properties to validate network destinations. JPMorgan Chase also confirmed and fixed a related issue in its open-source payments repository, while Weaviate and the French government’s open-data platform applied similar patches.

The Tangerang City government in Indonesia fixed a flaw in its INFOKOM-KI/Wazuh-MCP-Server, where the SSRF protection failed to resolve hostnames properly. Rapid7 also published a CVE for a different but related bug in its Bulk Export MCP. Despite these fixes, Mohiuddin reported that five MCP servers within U.S. federal agencies, including the Department of Veterans Affairs and the CDC, remain vulnerable, with no patches applied as of his latest update.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc