Security teams at Google, JPMorgan Chase, France's DINUM, the city government of Tangerang in Indonesia, and Weaviate have all fixed a server-side request forgery (SSRF) vulnerability in their Model Context Protocol (MCP) implementations. Independent researcher Syed Anas Mohiuddin identified the recurring flaw affecting various MCP servers used by AI agents to interact with external and internal tools.
- SSRF flaw allows unauthorized internal endpoint access via MCP servers
- Google, JPMorgan, French DINUM, Tangerang city, and Weaviate patched the issue
- Several US government MCP servers remain vulnerable and under triage
What happened
Researcher Syed Anas Mohiuddin discovered a critical server-side request forgery (SSRF) vulnerability impacting several MCP servers operated by high-profile organizations including Google, JPMorgan Chase, France’s DINUM, the Indonesian city government of Tangerang, and Weaviate. The flaw arises because MCP servers improperly validate URLs passed by AI agents and thereby can be tricked into making requests to arbitrary internal or external endpoints.
This vulnerability permits an attacker controlling the AI agent to pivot requests to internal network resources, potentially exposing sensitive information or internal infrastructure. Notably, these separate MCP servers were developed independently, confirming the vulnerability’s root cause as a structural design flaw in common MCP implementations. Several fixes have been deployed but some US government MCP services remain unpatched.
Why it matters
MCP is an emerging standard protocol that AI agents use to securely invoke external tools and data sources. The discovery of a shared SSRF issue across different sectors — from hyperscalers to national governments and major financial institutions — underscores systemic risks in the core architecture of AI tooling integration. If exploited, such SSRF bugs can lead to unauthorized data access, internal network reconnaissance, and abuse of trusted system components.
Because MCP servers often handle sensitive or critical information in enterprise and government contexts, these SSRF vulnerabilities carry significant operational and privacy risks. The recurring nature of the flaw highlights a need for widespread hardening of protocol implementations and stricter validation mechanisms to mitigate this class of protocol pivoting attacks.
What to watch next
Further monitoring is required to ensure MCP server operators continue patching vulnerable instances, especially US federal government deployments which remain in triage and unresolved as of October 2026. Security researchers will be watching closely for disclosures of new MCP-related threats or exploit attempts leveraging the protocol pivoting technique described by Mohiuddin.
Additionally, upcoming events such as MCPCon North America, where Mohiuddin will present detailed findings, may produce deeper insights and security recommendations for stakeholders developing or relying on MCP-based AI tooling. Organizations using MCP should prioritize implementing restrictive redirect policies, IP whitelisting, and DNS rebinding protections to mitigate similar SSRF risks.