Five organizations have disclosed the same class of flaw since May. One internal AI agent hands a hostile instruction to another internal agent, and the second runs it because it trusts the first.
- Researcher Syed Anas Mohiuddin tested agents at Google, JPMorgan Chase, Weaviate, Rapid7, the French government’s interministerial digital directorate and a US federal agency.
- MCP servers hold a credential for each agent and agents trust their internal peers, so an MCP prompt injection that the model itself would have refused gets executed by the plumbing instead.
- Google’s database toolbox carried no redirect policy and no target IP validation, so a crafted path parameter could reach an internal endpoint. The patch adds an IP allow-list. That flaw scored 8, against 2.7 for CVE-2026-97228 in Rapid7’s network.
- Much of the chain ends in an ordinary server-side request forgery, a twenty year old bug class that has had a standard fix for twenty years.
Read the full analysis of the trust gap between agents.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
