Analysis
Google, JPMorgan and the French Government Shipped the Same MCP Bug. Nobody Asked Who Controls the Argument
First reported · Discovered medium.com
Page published
Earliest dated coverage: 8 Oct 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 8 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Protocol Pivoting shows that a prompt-injection / request-forgery weakness in agent-to-agent MCP delegation recurs across unrelated high-profile MCP deployments, meaning defenders running MCP servers or clients must verify who controls the arguments passed between agents.
Medium author Andy.G analyzes independent researcher Syed Anas M's findings — covered by Ars Technica on October 5 — that MCP servers built by Google, JPMorgan, the French Government and others share the same request-forgery flaw, a pattern the researcher calls 'Protocol Pivoting' in which an injected instruction crosses from one agent to the next as ordinary delegated work. The write-up references CVE records and fix pull requests and offers guidance on spotting the flaw in one's own MCP stack.