Threat

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Page published

Earliest dated coverage: 5 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 5 Oct 2026

Coverage timeline

5 Oct 2026arstechnica.com

Single-source incident — one report is available.

Why it matters

MCP's assumption that internal agents can trust each other lets attackers chain prompt injection across an agent network to reach internal endpoints and exfiltrate sensitive data, a structural weakness affecting millions of organizations deploying AI agents.

Independent researcher Syed Anas Mohiuddin demonstrated a cross-agent prompt-injection technique that abuses trust gaps in the Model Context Protocol (MCP), where one compromised internal agent passes malicious instructions to downstream agents that implicitly trust it. Proof-of-concept attacks against agents from Google, JP Morgan Chase, Weaviate, Rapid7, and government bodies led to server-side request forgery and data exfiltration; Google's MCP database toolbox flaw (rated 8) and Rapid7's CVE-2026-97228 have both been fixed.