# AI agents’ trust gap lets attackers move between internal tools

> Researchers found that a flaw in the Model Context Protocol lets a compromised AI agent forward malicious prompts to other agents, affecting Google and four other firms.

Oossa · 2026-10-05 · https://oossa.com/en/ai-agents-trust-gap-lets-attackers-move-between-internal-tools

In the last five months, Google and four other organizations have disclosed a vulnerability that lets an attacker use one AI agent to give harmful instructions to other agents inside the same network. The problem lies in the Model Context Protocol (MCP), the standard many companies use for agents to talk to each other. When an agent receives a prompt it trusts, it may pass that prompt on without checking it, allowing the attacker’s code to hop from one tool to the next.

## How the flaw works

Independent researcher Syed Anas Mohiuddin showed that a specially crafted prompt can trigger a server‑side request forgery (SSRF) in agents that lack proper guardrails. In Google’s case, a toolbox for database agents initialized its HTTP client without a redirect‑checking policy, so a malicious URL could be followed to an internal endpoint. Google fixed the issue by adding IP allow‑lists and blocking unsafe base URLs at startup. Rapid7’s similar bug received a low severity score (2.7/10) and was patched last month.

## What this means for users

The attacks, called “protocol pivoting,” exploit the assumption that agents will trust each other automatically. Because many enterprises have rolled out AI agents quickly, they often skip the “zero‑trust” principle that would require each request to be authorized. As a result, a compromised agent can become a stepping stone for broader data theft or unauthorized network activity.

## The facts

- Google and four other firms reported MCP‑related vulnerabilities between May and October 2026.
- The Google flaw (CVE‑2026‑97228) received a severity rating of 8 out of 10.
- Rapid7’s MCP issue was rated 2.7 out of 10 and was patched in September 2026.
- MCP is the protocol that lets AI agents share tasks and data inside an organization’s internal network.
- The attack class is called “protocol pivoting,” a multi‑step exploit that moves from one protocol to another.

## Why it matters

For a business that relies on AI agents, the flaw means a single compromised tool could give an attacker access to other internal systems without triggering alerts. Organizations need to treat agent‑to‑agent communication like any other network traffic and add explicit authorization checks. Until such safeguards are widely adopted, the risk of data leaks or unauthorized actions remains uncertain.

## Sources & references

1. [Vulnerability in agents from Google and others exposes structural flaw in MCP](https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp/) – Ars Technica, 2026-10-05

Last updated: 2026-10-05
