Key facts
- AI agents from Google, JP Morgan Chase, and other organizations are vulnerable to 'protocol pivoting' attacks.
- These attacks exploit trust gaps in communication protocols like Model Context Protocol (MCP).
- Vulnerabilities allow malicious instructions to spread from one agent to another within an organization.
- The technique targets specific agents rather than the core LLM, leveraging lax guardrails.
- Google's vulnerability, rated 8 out of 10, involved an HTTP client that failed to validate IP addresses and handle redirects properly.
- Rapid7 fixed a similar vulnerability with a severity rating of 2.7.
A new class of cyberattacks, termed 'protocol pivoting,' is exploiting trust vulnerabilities between AI agents, enabling malicious instructions to spread within organizations. Researchers have identified such flaws in agents used by major entities including Google, JP Morgan Chase, and various government bodies.
These attacks leverage the Model Context Protocol (MCP), a standard for inter-agent communication. The core issue lies in the trust assumed between agents within a network; if one agent is compromised, it can relay malicious commands to other agents that inherently trust its input. Many specialized agents lack robust guardrails, making them susceptible to prompt injection techniques that can lead to actions like data exfiltration or unauthorized network requests, such as server-side request forgery (SSRF).
Independent researcher Syed Anas Mohiuddin demonstrated these exploits, finding vulnerabilities in agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government, and the US federal government. While Rapid7 fixed a low-severity vulnerability (CVE-2026-97228), Google addressed a more critical one (rated 8 out of 10) by enhancing its HTTP client's security to better handle URL redirects and validate IP addresses. Mohiuddin described the technique as 'protocol pivoting' due to its multi-step nature involving different communication protocols.
Experts note that this is a form of indirect prompt injection, and the widespread adoption of AI agents before thorough security hardening of communication protocols like MCP has left organizations exposed. The principle of 'zero trust,' where every network interaction requires authorization, is being overlooked in the rush to build complex agentic architectures.

