Google, JPMorgan and two governments fixed the same MCP flaw

https://media.thenextweb.com/2026/10/cables-plugged-into-back-panel-connectors-close-up.jpg

Security teams at Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate (DINUM) and the city government of Tangerang in Indonesia have each fixed the same type of flaw in their Model Context Protocol (MCP) servers. Independent researcher Syed Anas Mohiuddin reported all five, he wrote in an update published this month.

MCP is the standard AI agents use to call tools and data sources. The flaw is server-side request forgery (SSRF). An MCP server takes a URL, path or endpoint from an agent and builds an outbound request from it, without checking where the address actually resolves. That lets whoever steers the agent decide what the server talks to, including internal systems.

In May, Mohiuddin argued that the problem was structural. If it was, he predicted, teams that share no code or owner would all produce it.

“Watching the same mistake come back from a hyperscaler, a bank, and a...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more