Independent security researcher Syed Anas Mohiuddin found the same server-side request forgery flaw in Model Context Protocol servers built by five unrelated organizations, including Google and JPMorgan Chase, according to Unite.AI and The Next Web. The other three were Weaviate, France's digital administration agency DINUM and the city government of Tangerang, Indonesia. Mohiuddin had predicted the pattern in a May preprint, reasoning that if the weakness were structural rather than a single team's mistake, it would surface in servers written by groups sharing no code, industry or country.

The flaw lets an MCP server build an outbound network request from a URL or path supplied by an AI agent without checking where it actually points, so the agent effectively decides what the server's network identity talks to, The Next Web reported. Google's MCP Toolbox for Databases, versions 0.3.0 through 1.4.0, had no restrictive redirect policy or IP address check, a flaw tracked as CVE-2026-14540 with a severity score of 8.0 out of 10, according to both outlets.

JPMorgan Chase's documentation-search server validated some tools' URLs against an allowlist but not others, and its Responsible Disclosure team confirmed and patched the finding, Unite.AI reported. France's DINUM and the Tangerang city government each fixed similar flaws in their own MCP servers by early September, and five U.S. federal servers, including ones serving Veterans Affairs benefits claims and the CDC, remained in triage as of the researcher's October update, according to Unite.AI.

Rapid7's Douglas McKee, whose company fixed an unrelated MCP vulnerability in the same disclosure round, said "every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch," The Next Web reported. Researchers also described a related technique called protocol pivoting, in which text formatted like a legitimate agent-to-agent task is embedded in an MCP tool's response, and an orchestrating agent passes it to a subagent that executes it on trust, according to both outlets.

MCP servers are supposed to be the trusted middle layer between an agent and a company's data. A bug this consistent, found independently in five unrelated organizations' code, says the problem is not sloppy implementation but a gap in the protocol's own trust model, the exact kind of flaw that does not show up in a demo and only bites in production.