Home/Events/Vulnerability in AI Agents from Google, Rapid7, and Others Exposes Flaw in Model Context Protocol

Vulnerability in AI Agents from Google, Rapid7, and Others Exposes Flaw in Model Context Protocol

Confirmed
Confidence
80%
Impact: 70%
Updated 1h ago

Consensus Brief

A vulnerability affecting AI agents from Google, Rapid7, and several other organizations has been identified, allowing attackers to exploit trust gaps in the Model Context Protocol (MCP). This vulnerability enables malicious instructions to be passed between agents, leading to potential data exfiltration and unauthorized actions. The issue highlights a significant security oversight in the design of AI agent architectures.

Sourced from
Primary: Ars Technica

What Changed Since Last Update

1h ago

The discovery of the 'protocol pivoting' attack method reveals new risks associated with the use of MCP in AI agents, which were previously unaddressed.

Claim Ledger

3 claims tracked across sources

Confirmed Fact

CVE-2026-97228, the vulnerability found in Rapid7’s network, had a severity rating of 2.7 out of 10.

Confirmed Fact

The vulnerability affecting Google had a severity rating of 8.

Independent Finding

MCP is new and is already widely used before it has been sufficiently tested and hardened.

Role-Based Impact Analysis

Source Timeline

1 source corroborating