HomeSecurityGoogle, JPMorgan and two governments fixed the same MCP bug

Google, JPMorgan, and two governments fixed the same MCP bug

Security teams at Google, JPMorgan Chase, Weaviate, France’s Directorate of Digital Governance (DINUM), and the local government of the city of Tangerang in Indonesia have all fixed the same kind of bug in their Model Content Protocol (MCP). Independent researcher Syed Anas Mohiuddin reported on all five cases in an update published this month.

See also: Google Home opens the door to Claude, OpenClaw and other MCP agents

Article image: Google, JPMorgan and two governments fixed the same MCP flaw

MCP is the standard that AI agents use to call tools and data sources. The flaw is server-side request forgery (SSRF). An MCP server takes a URL, path, or endpoint from an agent and creates an outbound request from it, without checking where the address actually resolves. This allows whoever is running the agent to decide what the server communicates with, including internal systems.

In May, Mohiuddin argued that the problem was structural, predicting that groups without common code or ownership would all produce it. He noted, “Seeing the same bug reoccurring from a hyperscaler, a bank, and a national government, one report at a time, is when May’s prediction stopped being a guess.”

Google's MCP Toolbox for Databases had an HTTP client with no restrictive redirect policy and no control over target IP addresses, according to the warning on GitHub. A forged route parameter could send requests to internal or external endpoints. The flaw, CVE-2026-14540, has a high score of 8.0 and affects versions 0.3.0 through 1.4.0.

Google's fix adds DNS reconnection protection and lists of allowed and blocked IP addresses, giving credit to Mohiuddin.

JPMorgan's open source repository includes an MCP documentation search server with two tools that retrieve content. One checked domains against a whitelist, while its sibling tool retrieved any URL provided by the caller. JPMorgan forked the asset from an AWS project that never retrieved the caller's URL. The Responsible Disclosure team confirmed the finding and deployed a fix, which is rated medium severity.

See also: Google: Temporarily stops vulnerability reports in OSS VRP

MCP flaw - SecNews.gr

Weaviate restricted its Google module endpoint settings to Google API hosts. DINUM’s official MCP server for France’s open data platform was retrieving URLs provided by data producers, which could point to internal or cloud metadata addresses. Its fix, titled “SSRF enhancement in external APIs,” begins with “Reported by Syed Anas Mohiuddin.”

On the Wazuh MCP server in Tangerang, a tool advertised itself as SSRF protection but only rejected literal IP addresses. Hostnames were never resolved, according to a high severity alert posted on September 3.

Rapid7 has fixed a different bug found by Mohiuddin, CVE -2026-97228 , in its Bulk Export MCP server. This bug allowed GraphQL injection within operator access, and Rapid7 rates it low at 2.7.

On September 2, Mohiuddin reported privacy issues on five MCP servers under the U.S. General Services Administration’s Technology Transformation Office. These include servers for Veterans Affairs benefit applications, CMS Blue Button, regulations.gov, USASpending, and CDC PLACES. All five are still under review and have not been patched.

In the case of Veterans Affairs, the server logs full error responses from the unencrypted benefits API, which can include a veteran’s name, social security number, date of birth, and address. Mohiuddin is withholding code-level details until maintainers can fix the servers. His report on the Japan Digital Service’s grants server, which had no authentication, also remains open.

See also: Lawsuits against Google over AI Overviews dismissed

Google, JPMorgan, and two governments fixed the same MCP bug

Mohiuddin refers to the broader category of attacks as “protocol displacement.” An attacker can insert text into content returned by an MCP tool configured to work with Google’s A2A protocol. An orchestration agent passes it to a subagent.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS