Skip links

Exploring MCP: The High-Risk Protocol for Agent-to-Agent Communications

A recent discussion by Douglas McKee, director of vulnerability intelligence at Rapid7, has shed light on the evolving landscape of cybersecurity threats, particularly involving AI agents. McKee emphasized the unsettling implications of these agents, stating that they can create new pathways for attackers. In essence, if malicious text is embedded within content, an AI agent processes it and forwards it to another agent without scrutiny, trusting the initial source. This unmonitored delegation enables potentially harmful actions, as each system is designed to operate independently, concentrating on its own security without oversight of inter-agent interactions.

A specific vulnerability, cataloged as CVE-2026-97228, which was discovered in Rapid7’s systems, received a low severity rating of 2.7 out of 10. Nevertheless, this issue was resolved last month by Rapid7, illustrating their proactive approach to security.

In contrast, a more critical flaw recently uncovered at Google received a severity rating of 8 out of 10. This vulnerability originated from a component within the googleapis/mcp-toolbox which configured its HTTP client without implementing a proper CheckRedirect policy. This oversight allowed crafted path parameters to enable the toolbox to inadvertently redirect requests to an internal endpoint, potentially executing commands on behalf of the attacker. Google responded effectively by introducing an allow-list for IP ranges and block lists to enhance security measures.

The vulnerability has led Syed, the researcher behind the discovery, to coin the term “protocol pivoting” to describe a newly identified class of cyberattacks. This method exploits trust relationships between different protocols when an application or server assigns tasks to agents via MCP. The agents, in turn, may transmit malicious commands to other agents using distinct communication protocols. Syed pointed out that this often results in a breakdown of trust and authorization, complicating detection and prevention strategies.

He elaborated that this multi-faceted attack approach begins with initial access through one protocol, leveraging trust assumptions across various protocols, ultimately escalating an attacker’s capabilities through a different protocol.

Editor’s Take

The emergence of vulnerabilities like those found in Rapid7 and Google underscores a critical weakness in the security frameworks of AI-driven systems. As businesses increasingly adopt AI technologies, understanding these threats is vital. It raises essential questions about trust and verification across protocols, highlighting a need for ongoing scrutiny and enhanced security measures to protect sensitive data and user operations.

Source: arstechnica.com

Leave a comment