Critical Agent Flaws Reveal Widespread Protocol Pivoting Risk in MCP Deployments
Researcher Syed Anas Mohiuddin has uncovered a series of vulnerabilities across Google, JPMorgan Chase, Weaviate, France's DINUM and the city of Tangerang that expose a structural weakness known as protocol pivoting in multi‑model collaborative platforms.

Understanding Protocol Pivoting
The term "protocol pivoting" describes a scenario where a malicious instruction received by an AI‑driven agent is transformed into a seemingly legitimate request to an internal service, often manifesting as a server‑side request forgery (SSRF) or an injection attack. Mohiuddin’s research shows that this pattern recurs across a diverse set of organizations that rely on model‑to‑tool communication within the Multi‑Model Collaborative Platform (MCP) ecosystem.
Google’s high‑severity CVE‑2026‑14540
At Google, the vulnerability catalogued as CVE‑2026‑14540 received a CVSS base score of 8.0, indicating a high level of exploitability and impact. The flaw stemmed from insufficient validation of redirection URLs and IP addresses supplied by an agent before the request reached a downstream service. Google’s patch introduced strict allow‑lists, block‑lists, and a startup check that rejects unsafe configurations, effectively hardening the data‑flow path.
Other corporate and public sector incidents
JPMorgan Chase’s public repository contained a recovery tool that lacked any allow‑list, allowing arbitrary internal endpoints to be contacted. After the issue was reported, the firm removed the tool and added proper access controls. Weaviate responded with a targeted merge request (ID 12961) that narrowed the exposed endpoints, while France’s DINUM upgraded its SSRF defenses in September 2026. The city of Tangerang in Indonesia remedied its vulnerable service within roughly one day of discovery.
Rapid7’s separate tracking of CVE‑2026‑97228, a GraphQL injection with a CVSS score of 2.7, underscores that not all protocol‑pivoting‑related bugs share the same severity. The lower score reflects a limited attack surface, yet it still demonstrates the breadth of the problem across different request formats.
Key technical characteristics of protocol pivoting
- Agent receives untrusted input from a language model or user.
- Input is forwarded to a tool without proper sanitisation.
- The tool interprets the input as a trusted internal request.
- Resulting action exploits SSRF, injection, or misconfiguration.
Mohiuddin’s analysis highlights that the root cause is a trust assumption built into many MCP designs: the output of a model is treated as a reliable datum for downstream services. This assumption collapses when an attacker can influence model output, for example through prompt injection or adversarial examples.
The researcher recommends a zero‑trust architecture in which every value emitted by a model is re‑validated before it reaches any external tool. Such validation can include schema checks, allow‑list verification, and runtime sandboxing to ensure that no single malformed value can trigger a privileged operation.
Implications for organizations using MCP
Enterprises that have integrated language models with internal APIs must reassess their data‑flow pipelines. The presence of protocol pivoting means that a breach in one component can cascade into a broader compromise, potentially exposing sensitive internal services or data stores.
Regulators and auditors are likely to scrutinize MCP implementations for evidence of zero‑trust controls, especially in sectors such as finance and public administration where the disclosed incidents occurred.
For English‑speaking organizations, the practical change is clear: adopt strict input validation at every hand‑off point, enforce allow‑lists for internal service calls, and deploy monitoring that flags unexpected outbound requests originating from AI agents.
By treating model output as untrusted by default, firms can mitigate the risk of protocol pivoting and protect critical infrastructure from a new class of AI‑enabled attacks.
Future research directions
Mohiuddin suggests that further study should focus on automated detection of pivoting patterns in real‑time logs, as well as the development of standardized testing suites for MCP components.
Collaboration between academia, industry, and governmental bodies will be essential to establish best practices and share threat intelligence across the rapidly expanding AI‑driven ecosystem.
In summary, the series of vulnerabilities uncovered across Google, JPMorgan Chase, Weaviate, France’s DINUM and the city of Tangerang expose a structural weakness that, if left unchecked, could enable attackers to leverage AI agents as vectors for internal compromise.
The findings underscore the urgency for a paradigm shift toward zero‑trust validation of all model‑generated data, a move that promises to safeguard multi‑model collaborative platforms against sophisticated protocol‑pivoting exploits.
Sources
- Vulnerability in agents from Google and others exposes structural flaw in MCPArs Technica · October 6, 2026
- Protocol Pivoting: four months laterSyed Anas Mohiuddin · October 6, 2026



