By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Felly ViralFelly ViralFelly Viral
Notification Show More
Font ResizerAa
  • Home
  • Nigeria
    NigeriaShow More
    Common weeds and their scientific names with pictures in Nigeria
    October 6, 2026
    Oman announces 10-day special work permit scheme for 9 foreign professions
    October 6, 2026
    Canada relaxes work permit eligibility for spouses of selected workers
    October 6, 2026
    Canada outlines 14 programs linked to work permits for families of foreign workers
    October 6, 2026
    100+ popular Edo names and meanings for boys and girls 2022
    October 6, 2026
  • Technology
    TechnologyShow More
    OpenAI drops another batch of mathematical breakthroughs
    October 6, 2026
    Braid-creator Jonathan Blow on making the 'biggest puzzle game ever'
    October 6, 2026
    Xbox has secured exclusive GTA 6 streaming rights
    October 6, 2026
    Xbox has secured exclusive GTA 6 streaming rights
    October 6, 2026
    The best robot vacuum and mop deals during October Prime Day
    October 6, 2026
  • Sports
  • World News
    World NewsShow More
    What’s behind Israel’s growing shift to the right?
    October 7, 2026
    Sudan’s al-Burhan rejects talks, vows to retake all territory from RSF
    October 7, 2026
    South Sudan’s aid crisis deepens as food stocks run low
    October 7, 2026
    French mayor tear-gassed after shielding protesters from police
    October 7, 2026
    Many Nepalis swept away in the floods aren't officially dead, leaving families in limbo
    October 6, 2026
  • Politics
    PoliticsShow More
    Syrian embassy returns seized passport after 43 years
    October 7, 2026
    Tinubu speaks on death of Baba-Ahmed, read details
    October 7, 2026
    Politicians slam Trump’s suggestion that Iran ‘take’ San Diego, Los Angeles
    October 7, 2026
    Yemeni forces launch offensive to retake Houthi-held al-Waziiya in Taiz
    October 7, 2026
    Tension in Katsina as hisbah commander-general resigns
    October 6, 2026
  • Science
  • Entertainment
    EntertainmentShow More
    Stanley Tucci's wife Felicity Blunt: age, career, children, and net worth
    October 7, 2026
    HBO Max, Paramount+, and Discovery+ "will unify into a single service”
    October 6, 2026
    Paramount takes over Warner Bros in $110bn Hollywood merger
    October 6, 2026
    Former ‘American Idol’ singer Caleb Flynn gets life for wife’s murder
    October 6, 2026
    My DIL said I ruined our vacation photos and cropped me out — By afternoon, she was begging me
    October 6, 2026
  • Crypto
    CryptoShow More
    It looks like the Atlantic storm season may finally produce a hurricane
    October 6, 2026
    It looks like the Atlantic storm season may finally produce a hurricane
    October 6, 2026
    European Banking Consortium Launches Fully Compliant Tokenized Settlement Network Under MiCA
    October 4, 2026
    Your Next Million AI Users May Not Use English. That’s Why You Need to Cater to a Multilingual Market.
    October 3, 2026
    Crypto thieves attack man in home and threaten to kill pregnant wife's baby in 'horrific' robbery
    October 1, 2026
  • About Us
  • Contact
Reading: Google, JPMorgan and two governments fixed the same MCP flaw
Share
Font ResizerAa
Felly ViralFelly Viral
  • Home
  • Entertainment
  • Science
  • Technology
  • Business
  • Crypto
  • Health
  • Nigeria
  • Politics
  • Sports
  • World News
Search
  • Home
  • About Us
  • Contact Us
  • Categories
    • Nigeria
    • Technology
    • Entertainment
    • Science
    • Health
    • Sports
    • Politics
    • World News
    • Business
    • Crypto
Have an existing account? Sign In
Follow US
Felly Viral > Blog > Technology > Google, JPMorgan and two governments fixed the same MCP flaw
Technology

Google, JPMorgan and two governments fixed the same MCP flaw

admin
Last updated: October 6, 2026 12:00 am
admin Published October 6, 2026
Share
SHARE
October 6, 2026 at 12:00 amIn: Technology

Credit: Manuel Luikenga on Unsplash Security teams at Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate (DINUM) and the city government of Tangerang in Indonesia have each fixed the same type of flaw in their Model Context Protocol (MCP) servers. Independent researcher Syed Anas Mohiuddin reported all five, he wrote in an update published this month. MCP is the standard AI agents use to call tools and data sources. The flaw is server-side request forgery (SSRF).

An MCP server takes a URL, path or endpoint from an agent and builds an outbound request from it, without checking where the address actually resolves. That lets whoever steers the agent decide what the server talks to, including internal systems. In May, Mohiuddin argued that the problem was structural. If it was, he predicted, teams that share no code or owner would all produce it. “Watching the same mistake come back from a hyperscaler, a bank, and a national government, one report at a time, is the moment the May argument stopped being a guess,” Mohiuddin wrote.

Five fixes Google’s MCP Toolbox for Databases had an HTTP client with no restrictive redirect policy and no check on target IP addresses, according to the GitHub advisory. A crafted path parameter could send its requests to internal or external endpoints. The flaw, CVE-2026-14540, carries a high rating of 8.0 and affects versions 0.3.0 to 1.4.0. Google’s fix adds a guard against DNS rebinding and lists of allowed and blocked IP ranges, and credits Mohiuddin.

JPMorgan’s open-source repository includes a documentation-search MCP server with two tools that fetch content. One checked domains against an allowlist. Its sibling fetched any URL the caller supplied, Mohiuddin wrote. JPMorgan forked the component from an AWS project that never fetched the caller’s URL at all.

JPMorgan’s Responsible Disclosure team confirmed the finding and deployed a fix, he wrote. The finding is medium severity, he wrote. Weaviate restricted its Google module’s endpoint settings to Google API hosts, he wrote. DINUM’s official MCP server for France’s open-data platform fetched URLs supplied by data producers, which could point at internal or cloud metadata addresses.

Its fix, titled “harden SSRF on external APIs”, opens with “Reported by Syed Anas Mohiuddin”. In Tangerang’s Wazuh MCP server, a tool advertised SSRF protection but only rejected literal IP addresses, according to a high-severity advisory published on 3 September. It never resolved hostnames. Rapid7 fixed a different bug he found, CVE-2026-97228, in its Bulk Export MCP server.

The bug allowed GraphQL injection within the operator’s own access, and Rapid7 rates it low, at 2.7, its database entry says. Still open On 2 September, Mohiuddin privately reported issues in five MCP servers under the US General Services Administration’s Technology Transformation Services. They include servers for Veterans Affairs benefits claims, CMS Blue Button, regulations.gov, USASpending and CDC PLACES. All five are still in triage and not fixed, he wrote.

In the Veterans Affairs case, the server logs full error responses from the benefits API without redaction, according to Mohiuddin. Those can contain a veteran’s name, Social Security number, date of birth and address. He is withholding code-level detail until maintainers patch the servers. His report on Japan’s Digital Agency grants server, which had no authentication, also remains open. ‘Protocol pivoting’ Mohiuddin calls the wider attack class “protocol pivoting”.

An attacker plants text in content an MCP tool returns, shaped like a task for Google’s A2A protocol. An orchestrating agent passes it to a subagent, which runs it because it trusts the orchestrator. “Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch,” Douglas McKee, Rapid7’s director of vulnerability intelligence, told Ars Technica. Markus Vervier of X41 D-Sec told Ars that the technique is a form of indirect prompt injection. Mohiuddin will present the findings at MCPCon North America in San Jose on 23 October.

You Might Also Like

Gemini 3.8 Live with Live Avatar gives Google’s AI a face

Apple Is Preparing to Release a Wave of New Products. Here’s What to Expect.

LG TVs caught spying even when offline or on standby

A Texas judge has found TikTok liable for misleading parents about child safety

Five makers, one laptop: Googlebook pre-orders open from $899

Share This Article
Facebook Twitter Email Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

What's Hot

Badenoch accuses Burnham of kicking defence spending into the long grass

Zack Polanski says he'll run for former PM Starmer's seat in by-election

Tragedy averted as fan slips and falls in front of Burna Boy's ₦9bn Bugatti

Rewetting peatlands may curb warming-driven CO₂ emissions

Davido reacts to video of Burna Boy taking delivery of his ₦9billion customised Bugatti Chiron

Bridging interfacial water structure and reactivity in photocatalytic hydrogen evolution at TiO₂ interfaces

Categories

Business

247 Articles

Politics

988 Articles
- Advertisement -
Ad image

Categories

  • Sports
  • Politics
  • Technology
  • Science
  • World News
  • Entertainment
  • Business
  • Nigeria
  • Health
  • Crypto

About US

Welcome to Felly Viral, your destination for the latest trends, breaking stories, engaging updates, and conversations shaping the world around us
Quick Link
  • Home
  • About Us
  • Contact
  • Member Login
  • Profile
  • My Bookmarks
  • Privacy Policy
  • Terms and Conditions
Top Categories
  • Entertainment
  • Sports
  • World News
  • Politics
  • Technology
  • Science
  • Business
  • Health
  • Crypto

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© Foxiz News Network. Ruby Design Company. All Rights Reserved.

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by
Welcome Back!

Sign in to your account