Independent researcher Syed Anas Mohiuddin discovered a critical prompt injection vulnerability in the Model Context Protocol (MCP), used by AI agents at Google, JP Morgan Chase, Rapid7, and government agencies to communicate internally. The exploit leverages inter-agent trust — one compromised agent can relay malicious instructions to another that blindly follows them due to stored credentials and lax guardrails.
Background
MCP (Model Context Protocol) is an open standard by Anthropic for AI agents and applications to communicate with each other and access tools within internal networks. It has been adopted by major tech companies and government agencies for multi-agent AI workflows.
- Source
- Ars Technica
- Published
- Oct 6, 2026 at 06:26 AM
- Score
- 8.0 / 10