Prompt injection over MCP enables 'protocol pivoting' between AI agents; Rapid7 responds with A2A security guidance
Researcher Syed Anas Mohiuddin demonstrated prompt-injection pivoting attacks over the Model Context Protocol against agents at Google, JPMorgan Chase, Rapid7, Weviate, and government bodies, prompting fixes and a Rapid7 call for identity and least-privilege…
On October 5, 2026, Ars Technica reported that researcher Syed Anas Mohiuddin had shown proof-of-concept 'protocol pivoting' attacks in which malicious instructions injected over the Model Context Protocol (MCP) are accepted by weakly guarded agents and forwarded to trusted agents, often resulting in server-side request forgery. Targets included AI agents at Google, JPMorgan Chase, Rapid7, Weviate, France's interministerial digital directorate, and the US federal government. Rapid7's CVE-2026-97228, scored 2.7, was patched; Google's mcp-toolbox flaw, rated 8, followed redirects without validating target IP addresses until an allow-list fix was deployed. X41 D-Sec researcher Markus Vervier characterized the technique as indirect prompt injection. Rapid7 advises treating LLM-to-tool content as untrusted input. The following day, October 6, 2026, Rapid7 published guidance arguing that autonomous agents delegating work via protocols such as MCP break security models built for human users and static APIs. It cited identity and delegation chaining blind spots, behavioral drift that can hide prompt injection, tool abuse leading to data exfiltration, cascading access from a compromised high-privilege agent, and gaps in reconstructing multi-agent decisions. Rapid7 recommends auditing agents, least-privilege task-scoped credentials, structured inter-agent logs and telemetry, and feeding agent events into detection workflows, including its own platform.
- Researcher Syed Anas Mohiuddin reported proof-of-concept 'protocol pivoting' attacks against AI agents at Google, JPMorgan Chase, Rapid7, Weviate, France's interministerial digital directorate, and the US federal government.
- CVE-2026-97228 (Rapid7) was scored 2.7 and has been patched.
- Google's mcp-toolbox flaw was rated 8; it followed redirects without validating target IPs until an allow-list fix.
- Malicious prompts can cross from MCP into A2A or other agent protocols, frequently causing server-side request forgery (SSRF).
- X41 D-Sec researcher Markus Vervier describes the technique as indirect prompt injection.
- Rapid7 says LLM-to-tool content should be treated as untrusted input.
- Rapid7's October 6 guidance cites identity/delegation chaining gaps, behavioral drift masking prompt injection, tool abuse enabling data exfiltration, cascading access from compromised high-privilege agents, and poor reconstructability of…
- Rapid7 recommends agent audits, least-privilege task-scoped credentials, structured inter-agent telemetry and logs, behavioral baselines to flag unusual communication or privilege changes, and routing agent events into detection workflows.
Coverage timelineoldest first · each row is one article
- · 3d agoMCP for agent-to-agent comms may the the riskiest protocol you've never heard of
Ars Technica · Security· 74
Researcher finds MCP trust gaps that let prompt injection pivot between agents at Google, Rapid7, and others.
- · 2d agoSecuring Agent-to-Agent Communication: The Next Identity Frontier
Rapid7 Blog· 36
Rapid7 urges identity, least-privilege, and telemetry controls for autonomous AI agent-to-agent communication.
Vulnerabilities in this storyAll →
- CVE-2026-972282.7—Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-97228 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in… Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the `check_rapid7_export_status` and `download_rapid7_export` tools — is interpolated directly into the GraphQL query string. A crafted `export_id` containing quote and brace characters can terminate the intended `export(id: "...")` selection early and append attacker-controlled root-level selections (for example, schema introspection), producing a single well-formed GraphQL document that is then sent to the Rapid7 export API under the operator's own API key. Notably, this issue does not grant an existing actor any access they do not already have: every injected query executes within the operator's own already-authenticated API scope, using the operator's own valid API key, and cannot cross a tenant or account boundary. A directly-malicious operator gains nothing they could not already do by calling the API directly; the realistic exposure is limited to a compromised or careless upstream MCP client, or indirect prompt injection forwarding an unvalidated identifier. This is fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`). |