Structural flaw in MCP lets AI agents spread malicious instructions to each other
Independent researcher Syed Anas Mohiuddin tested agents from Google, JP Morgan Chase, Weaviate, Rapid7 and two government bodies, exposing trust gaps in the MCP protocol. The attack compromises a single agent and uses it to relay harmful instructions to other agents in the chain. Five organizations have acknowledged such vulnerabilities over the past five months.