{"id":922752,"date":"2026-10-06T12:20:13","date_gmt":"2026-10-06T12:20:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/922752\/"},"modified":"2026-10-06T12:20:13","modified_gmt":"2026-10-06T12:20:13","slug":"mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-youve-never-heard-of","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/922752\/","title":{"rendered":"MCP for agent-to-agent comms may be the riskiest protocol you&#8217;ve never heard of"},"content":{"rendered":"<p>\u201cAI agents give attackers a fresh set of connections to walk across,\u201d Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. \u201cSomeone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.\u201d<\/p>\n<p>CVE-2026-97228, the vulnerability Syed found in Rapid7\u2019s network, carried a severity rating of only 2.7 out of 10. Rapid7 <a href=\"https:\/\/www.rapid7.com\/db\/vulnerabilities\/cve-2026-97228\/\" rel=\"nofollow noopener\" target=\"_blank\">fixed it<\/a> last month.<\/p>\n<p>The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis\/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL either returning an error or redirecting to a different URL. Google\u2019s HTTP client also failed to validate target IP addresses.<\/p>\n<p>\u201cA crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker\u2019s behalf,\u201d Syed <a href=\"https:\/\/anas-security-portfolio.vercel.app\/protocol-pivoting-update.html\" rel=\"nofollow noopener\" target=\"_blank\">explained<\/a>. Google\u2019s fix involved applying an allow-list of IP ranges and block lists. \u201cIt rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done.\u201d<\/p>\n<p>Syed is calling the class of attack \u201cprotocol pivoting\u201d because the exploits work when an app or server uses MCP to assign a task to an agent and the agent then forwards malicious instructions to another agent using a different communication method such as Google\u2019s Agent-to-Agent (A2A) protocol, used for inter-agent delegation, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization gets effectively lost in translation. He described protocol pivoting as \u201ca multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"\u201cAI agents give attackers a fresh set of connections to walk across,\u201d Douglas McKee, director of vulnerability intelligence&hellip;\n","protected":false},"author":2,"featured_media":922753,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[62,276,277,49,48,61],"class_list":["post-922752","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/922752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=922752"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/922752\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/922753"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=922752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=922752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=922752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}