Google, JPMorgan and two governments fixed the same MCP flaw
Researcher Syed Anas Mohiuddin reported the same SSRF flaw in MCP servers at Google, JPMorgan Chase, Weaviate, France's DINUM and Indonesia's Tangerang city government. Google's issue is tracked as CVE-2026-14540 with a high 8.0 rating, affecting versions 0.3.0 to 1.4.0; all five have shipped fixes. Five US GSA MCP servers and Japan's Digital Agency server remain unfixed.
- CVE-2026-14540 in Google MCP Toolbox for Databases rated 8.0, versions 0.3.0–1.4.0
- JPMorgan, Weaviate, DINUM and Tangerang patched after Mohiuddin's reports
- Five US GSA MCP servers (VA, CMS, regulations.gov and others) still unfixed
- VA server logs leak veterans' names, SSNs and addresses in error responses
Read next
Security