Oossa

AI agents’ trust gap lets attackers move between internal tools

Researchers found that a flaw in the Model Context Protocol lets a compromised AI agent forward malicious prompts to other agents, affecting Google and four other firms.

By Published by Oossa: 1 min read

selcuk sarikoz · Unsplash

In the last five months, Google and four other organizations have disclosed a vulnerability that lets an attacker use one AI agent to give harmful instructions to other agents inside the same network. The problem lies in the Model Context Protocol (MCP), the standard many companies use for agents to talk to each other. When an agent receives a prompt it trusts, it may pass that prompt on without checking it, allowing the attacker’s code to hop from one tool to the next.

How the flaw works

Independent researcher Syed Anas Mohiuddin showed that a specially crafted prompt can trigger a server‑side request forgery (SSRF) in agents that lack proper guardrails. In Google’s case, a toolbox for database agents initialized its HTTP client without a redirect‑checking policy, so a malicious URL could be followed to an internal endpoint. Google fixed the issue by adding IP allow‑lists and blocking unsafe base URLs at startup. Rapid7’s similar bug received a low severity score (2.7/10) and was patched last month.

What this means for users

The attacks, called “protocol pivoting,” exploit the assumption that agents will trust each other automatically. Because many enterprises have rolled out AI agents quickly, they often skip the “zero‑trust” principle that would require each request to be authorized. As a result, a compromised agent can become a stepping stone for broader data theft or unauthorized network activity.

Why it matters

For a business that relies on AI agents, the flaw means a single compromised tool could give an attacker access to other internal systems without triggering alerts. Organizations need to treat agent‑to‑agent communication like any other network traffic and add explicit authorization checks. Until such safeguards are widely adopted, the risk of data leaks or unauthorized actions remains uncertain.

Was this article useful?
Share

Read next

Oossa · Newsletter

The week in AI, explained

Every Monday: the stories worth knowing, in plain language. Free, no spam.