Majorsafety alignmentGoogle

Vulnerabilities in Model Context Protocol Expose AI Agents to Attacks

Published
Oct 5, 2026 — 22:26 UTC
Also in this story:JP Morgan ChaseRapid7

The Model Context Protocol (MCP) has been identified as a significant vulnerability affecting AI agents from Google, JP Morgan Chase, Weviate, and Rapid7, with a severity rating of 8 out of 10 for Google’s implementation. Over the past five months, these organizations, along with the French government’s interministerial digital directorate and the US federal government, have acknowledged these vulnerabilities. The specific CVE-2026-97228 has a severity rating of 2.7 out of 10.

Douglas McKee, Director of Vulnerability Intelligence at Rapid7, noted that AI agents provide attackers with new pathways for exploitation, stating, "AI agents give attackers a fresh set of connections to walk across." Independent researcher Syed Anas Mohiuddin highlighted a potential attack vector where a crafted path parameter could redirect requests to internal endpoints, effectively allowing attackers to act on behalf of the system.

Markus Vervier from X41 D-Sec referred to these vulnerabilities as a form of indirect prompt injection, emphasizing that malicious prompts could originate from different protocols, such as agent-to-agent communication, and still exploit the system. McKee advised that any data passed from a large language model (LLM) to tools should be treated with caution, akin to input from an untrusted source.

Rapid7 implemented a fix for these vulnerabilities last month, but the ongoing risks associated with MCP highlight the need for enhanced security measures in AI agent communications. This follows previous coverage of AI vulnerabilities, underscoring the critical need for robust security protocols in AI systems.

Summarised from Ars Technica AI's original report by the Turing Wire Newsdesk. Read the original for the full story.

Source: Ars Technica AI