📣 Send us your press release
Site updates every 15 minutes
Technology

MCP protocol creates risks for AI agent communications

New research reveals that the MCP protocol, used for AI agent-to-agent communication, can expose organizations to security risks. Vulnerabilities allow the spread of malicious instructions between internal agents.

5 October 2026
MCP protocol creates risks for AI agent communications

The widespread adoption of AI agents in organizations is creating new avenues for attackers to exploit. Independent researcher Syed Anas Mohiuddin has identified that the Model Context Protocol (MCP), used for communication between AI applications and agents within an internal network, can pose a significant security risk.

Over the past five months, several organizations, including Google and JP Morgan Chase, have reported vulnerabilities where one agent within a targeted network has been able to spread malicious commands to other internal agents. This attack technique is a variant of prompt injection that targets the agent directly, rather than the language model itself.

The vulnerability in the MCP protocol exploits the trust between agents. When one agent receives a malicious instruction, it forwards it to other internal agents that assume it comes from a trusted source. The agents' internal safeguards are often insufficient or non-existent, allowing malicious commands to propagate through the system.

According to Mohiuddin, the vulnerability is unexpected and difficult to mitigate. The issue affects multiple organizations with little in common except their use of AI agents. These organizations include Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the U.S. federal government.

This discovery highlights the need for developing more secure protocols for AI agent communication to prevent data exfiltration and other malicious activities.

Original source: arstechnica.com