Google, JPMorgan, and Two Governments Exposed by Recurring MCP Server Flaw
Source
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Ars Technica
Via Ars Technica
What happened
Researchers disclosed a recurring server-side request forgery weakness in MCP servers operated by five named organizations: Google, JPMorgan Chase, Weaviate, France's DINUM, and Tangerang City. The flaw lets an attacker or compromised AI agent manipulate where an agent's outbound requests are sent. MCP, or Model Context Protocol, is the emerging standard for connecting AI agents to external tools, data sources, and other agents. As reported by Ars Technica, agents exploiting the flaw could pivot malicious instructions across agent-to-agent communication paths, effectively using one compromised agent as a launchpad against others. The site has previously covered 68 MCP Server CVEs in One Month. It has also covered a CVE-2026-75130 MCP bug with no documented fix. This research follows that broader pattern of MCP security failures. Researchers concluded that MCP deployments need destination validation, network isolation, explicit authorization for sensitive inter-agent transactions, and security testing of delegation paths.
Why it matters
- ·The named victims include a global systemically important bank and two government bodies. Regulators monitoring these sectors will scrutinize MCP deployments under the EU AI Act (Regulation (EU) 2024/1689) and financial sector model risk frameworks.
- ·The flaw is structural and recurring, not a single misconfiguration. It reappeared across five unrelated organizations using MCP. Any compliance team that approved an MCP-based agentic deployment without reviewing outbound request controls and inter-agent authorization has an open gap in its current risk posture.
- ·Agent-to-agent attacks bypass the controls most organizations rely on. Human approval gates and logging are typically set where a human interacts with an agent, not along internal agent-to-agent paths. This finding directly challenges the assumption that oversight of the first agent in a chain is sufficient.
Governance controls affected
What to do now
- ☐Ask your engineering or infrastructure team to produce a list of every MCP server your organization operates or connects to, including those managed by third-party vendors, and confirm which ones are in production with live agent traffic.
- ☐For each MCP server identified, ask whether outbound requests from agents are validated against an approved list of destinations, or whether an agent can be instructed to send requests to arbitrary internal or external addresses.
- ☐Review whether your inter-agent communication paths, meaning cases where one AI agent instructs or calls another, require explicit authorization before sensitive actions are taken, and document where no such requirement exists.
- ☐Instruct your security team to include MCP delegation paths in the next scheduled adversarial test of your agentic systems, specifically testing whether a compromised downstream agent can relay instructions back upstream.
- ☐If your organization is a financial institution or government body, assess whether this finding must be disclosed under existing model risk management or operational resilience reporting requirements, and log the assessment decision with rationale.
What to watch next
The breadth of named victims across private and public sectors will likely draw regulatory attention to MCP as infrastructure requiring formal security review, not just vendor assurance. Compliance teams should watch for updated guidance from the Five Eyes Guidance on the Careful Adoption of Agentic AI Services. They should also monitor financial regulators who have already signaled concern about agentic risk in bank supervision. Recurring MCP vulnerabilities now span dozens of CVEs and multiple named enterprises. This pattern is likely to inform forthcoming standards work. Watch for updates to the CIS MCP Benchmark and related agent security baselines.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI systems built to extend your reach are now extending attackers' reach too, and regulators in California and South Korea are making clear that containment failures belong to deployers, not just vendors.8 Oct
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
Free every Thursday. Unsubscribe anytime.
