October 6, 2026
MCP-for-agent-to-agent-communications-may-be-the-riskiest-protocol-youve.jpg

“AI agents give attackers a new set of connections to cross,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. “Someone puts text into the content, an agent reads it, and then passes it to another agent as a normal delegated task, and that second agent executes it because they trust whoever gave them the job. Each piece of that chain did exactly what it was designed to do, which is what makes this so difficult to detect. Each protocol was created assuming it lived on its own, so each one checks its own front door while no one watches the hallway in between.”

CVE-2026-97228, the vulnerability Syed found in Rapid7’s network, had a severity rating of just 2.7 out of 10. Rapid7 fixed it last month.

The vulnerability that affected Google was more severe, with a rating of 8. It came from an MCP toolbox for databases (googleapis/mcp-toolbox) that initialized its HTTP client without the use of a CheckRedirect policy, a series of settings that control how a server should handle cases where a URL returns an error or redirects to a different URL. Google’s HTTP client was also unable to validate destination IP addresses.

“A crafted route parameter could cause the toolbox to follow a redirect to an internal endpoint and send requests on behalf of the attacker,” Syed explained. Google’s solution involved applying an allow list of IP ranges and block lists. “It rejects an insecure base URL at startup instead of on the first request. This is what a real SSRF guard looks like. It’s also more work than most MCP servers have done.”

Syed calls this class of attack “protocol pivoting” because exploits work when an application or server uses MCP to assign a task to an agent and then the agent sends malicious instructions to another agent using a different communication method, such as Google’s Agent-to-Agent (A2A) protocol, used for delegation between agents, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization is effectively lost in translation. He described the pivoting protocol as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities that can only be accessed through a different protocol.”

Avatar photo
Written by

Jhon Smith

Info Vitalis is a content writer specializing in creating clear, concise, and engaging articles. With experience in health, lifestyle, technology, and current events, Info Vitalis aims to provide readers with useful and easy-to-understand information.

Leave a Reply

Your email address will not be published. Required fields are marked *