Credit: Manuel Luikenga on Unsplash Security teams at Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate (DINUM) and the city government of Tangerang in Indonesia have each fixed the same type of flaw in their Model Context Protocol (MCP) servers. Independent researcher Syed Anas Mohiuddin reported all five, he wrote in an update published this month. MCP is the standard AI agents use to call tools and data sources. The flaw is server-side request forgery (SSRF).
An MCP server takes a URL, path or endpoint from an agent and builds an outbound request from it, without checking where the address actually resolves. That lets whoever steers the agent decide what the server talks to, including internal systems. In May, Mohiuddin argued that the problem was structural. If it was, he predicted, teams that share no code or owner would all produce it. “Watching the same mistake come back from a hyperscaler, a bank, and a national government, one report at a time, is the moment the May argument stopped being a guess,” Mohiuddin wrote.
Five fixes Google’s MCP Toolbox for Databases had an HTTP client with no restrictive redirect policy and no check on target IP addresses, according to the GitHub advisory. A crafted path parameter could send its requests to internal or external endpoints. The flaw, CVE-2026-14540, carries a high rating of 8.0 and affects versions 0.3.0 to 1.4.0. Google’s fix adds a guard against DNS rebinding and lists of allowed and blocked IP ranges, and credits Mohiuddin.
JPMorgan’s open-source repository includes a documentation-search MCP server with two tools that fetch content. One checked domains against an allowlist. Its sibling fetched any URL the caller supplied, Mohiuddin wrote. JPMorgan forked the component from an AWS project that never fetched the caller’s URL at all.
JPMorgan’s Responsible Disclosure team confirmed the finding and deployed a fix, he wrote. The finding is medium severity, he wrote. Weaviate restricted its Google module’s endpoint settings to Google API hosts, he wrote. DINUM’s official MCP server for France’s open-data platform fetched URLs supplied by data producers, which could point at internal or cloud metadata addresses.
Its fix, titled “harden SSRF on external APIs”, opens with “Reported by Syed Anas Mohiuddin”. In Tangerang’s Wazuh MCP server, a tool advertised SSRF protection but only rejected literal IP addresses, according to a high-severity advisory published on 3 September. It never resolved hostnames. Rapid7 fixed a different bug he found, CVE-2026-97228, in its Bulk Export MCP server.
The bug allowed GraphQL injection within the operator’s own access, and Rapid7 rates it low, at 2.7, its database entry says. Still open On 2 September, Mohiuddin privately reported issues in five MCP servers under the US General Services Administration’s Technology Transformation Services. They include servers for Veterans Affairs benefits claims, CMS Blue Button, regulations.gov, USASpending and CDC PLACES. All five are still in triage and not fixed, he wrote.
In the Veterans Affairs case, the server logs full error responses from the benefits API without redaction, according to Mohiuddin. Those can contain a veteran’s name, Social Security number, date of birth and address. He is withholding code-level detail until maintainers patch the servers. His report on Japan’s Digital Agency grants server, which had no authentication, also remains open. ‘Protocol pivoting’ Mohiuddin calls the wider attack class “protocol pivoting”.
An attacker plants text in content an MCP tool returns, shaped like a task for Google’s A2A protocol. An orchestrating agent passes it to a subagent, which runs it because it trusts the orchestrator. “Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch,” Douglas McKee, Rapid7’s director of vulnerability intelligence, told Ars Technica. Markus Vervier of X41 D-Sec told Ars that the technique is a form of indirect prompt injection. Mohiuddin will present the findings at MCPCon North America in San Jose on 23 October.











Leave a Reply