Vulnerability in Google and other AI agents exposes structural flaw in MCP
Independent researcher Syed Anas Mohiuddin found a "protocol pivoting" attack that relays malicious instructions between internal AI agents via MCP and A2A. A Rapid7 flaw was rated 2.7 out of 10, while Google's was rated 8; both have been fixed.
- Attack exploits trust between internal agents communicating over MCP
- Google's googleapis/mcp-toolbox flaw was rated 8 out of 10
- Rapid7's CVE-2026-97228 scored only 2.7 out of 10
- Agents at Google, JP Morgan Chase, Rapid7 and government bodies affected
Read next
Security