On October 5, 2026, Ars Technica reported the discovery of a structural trust flaw in Model Context Protocol (MCP), a standard designed for messaging between artificial-intelligence agents. Independent researcher Syed Anas Mohiuddin built attack demonstrations against agents belonging to Google, JPMorgan Chase, Rapid7, Weviate, France's interministerial digital directorate, and US federal systems; over the past five months, the same class of vulnerability was confirmed in every case. This is not about an isolated coding bug — the problem is described as a systemic defect in the protocol's own trust model.

What MCP is and where it is used

Model Context Protocol is a standard that lets AI applications and agents exchange messages with one another across internal networks. It simplifies how agents connect to data sources and tools, which is why it is spreading quickly through corporate systems. The catch is that these same centralized connection points make a convenient target for attackers as well: every message passing through the protocol is treated as trustworthy.

The root of the problem is that MCP servers are treated as both central and trusted at the same time. Agents send messages to one another through the server, and those messages pass no additional checks by default — they are considered safe simply because they come from inside the system.

How the vulnerability works

According to Ars Technica's account, the flaw arises from three factors combined. First, specialized AI agents are often released with weak protection or none at all. Second, MCP servers store the credentials of every agent on the network — the keys needed to act on agents' behalf are concentrated on the server. Third, agents trust one another by default. As a result, a single compromised agent becomes a foothold for an attacker to move laterally across the entire network.

The most dangerous part is how attack messages are packaged. A large language model (LLM) will usually detect and refuse a directly given malicious command. But if that same command is repackaged as a message from a trusted internal source, it passes unimpeded inside the inter-agent trust chain — because the receiving agent interprets the message not as an external attack but as a request from a trusted colleague.

In such an architecture, compromising one weak agent is enough for the attacker: through it, they send other agents instructions that look trustworthy. Each subsequent agent, trusting the previous one, executes the request — the chain continues this way, and the attack spreads across the whole network.

Confirmed in more than five organizations over five months

The researcher built attack demonstrations not against a single company but against agents of several independent organizations: Google, JPMorgan Chase, Rapid7, Weviate, France's interministerial digital directorate, and US federal systems. In every case the same class of vulnerability was confirmed, and the process lasted the past five months. So the issue is not one product's bug — it is a common architectural problem recurring in agents from different vendors.

The fact that the attack demonstrations took five months to prepare and showed the same type of vulnerability in systems from different vendors is grounds for treating this not as an accidental bug in a single product but as a recurring architectural problem.

The Rapid7 and Google cases

CVE-2026-97228, found in Rapid7's network, scored 2.7 out of 10, and the company patched it last month. The fix shipped in release v0.6.2 of the rapid7-bulk-export-mcp package: export_id is passed to the GraphQL query as a parameterized variable, closing the query-injection path. Release details were published on the package's GitHub page.

The Google-related issue was rated far more seriously — 8 out of 10. According to Ars Technica's article, the googleapis/mcp-toolbox package ran its HTTP client without a CheckRedirect policy and did not validate target IP addresses. A specially crafted path parameter could force the tool to follow a redirect to an internal endpoint and send requests on the attacker's behalf. As a fix, Google introduced IP allow and deny lists and now rejects insecure base URLs at startup.

The researcher's conclusion

"AI agents give attackers a whole new set of connections to traverse — each protocol guards its own door, but nobody is watching the hallway in between," Rapid7's director of vulnerability intelligence Douglas McKee told Ars Technica.

Rapid7 announced its fix in release v0.6.2, and Google also hardened protections in its tool. At the same time, the problem the researcher found is described not as isolated coding errors but as a systemic issue tied to the protocol's own trust model.