Researcher shows prompt injections relayed between MCP-connected agents at Google, JPMorgan Chase and government agencies
Ars Technica reported on Oct 5, 2026 that independent researcher Syed Anas Mohiuddin got prompt injections planted in low-stakes internal agents to be passed on, over the Model Context Protocol, to more privileged agents at Google, JPMorgan Chase, Weaviate, Rapid7, the French government's digital directorate and a US federal agency. Downstream agents trusted upstream ones, enabling data theft and SSRF.
Key facts
- Attack: a crafted prompt injection aimed at a harmless-looking internal agent (e.g. for data analysis or translation), whose weak or absent guardrails let it relay the instructions to other agents down the chain (Ars Technica, via mirror)
- Affected per the report: agents tied to Google, JPMorgan Chase, Weaviate, Rapid7, France's interministerial digital directorate (DINUM) and the US federal government; demonstrated outcomes included data exfiltration and server-side request forgery
- Framing: Ars calls MCP for agent-to-agent communication 'the riskiest protocol you've never heard of', arguing the flaw is structural: downstream agents explicitly trust upstream agents
What happened
Ars Technica described research by Syed Anas Mohiuddin showing that in multi-agent systems wired together with MCP, a single compromised "helper" agent can pass malicious instructions to the agents that hold real permissions, because those agents treat upstream agents as trusted. According to the report's summary, five organizations, including Google, have acknowledged such agent flaws over the past five months.
Why it matters
As companies chain specialised agents together, the weakest agent sets the security of the whole chain. The report adds to 2026's run of agent-security incidents and to pressure on MCP's design.
Unverified: our tools could not load arstechnica.com; facts come from a syndicated copy and search snippets. Vendor responses, CVE numbers and bounty details were not read. Confidence is medium until the original is read.
Changelog
- 2026-10-06: created (01:30 quick run, sweep 2026-10-06)
Related events
Sources (1)
id: 2026-10-05-mcp-agent-to-agent-prompt-injection-flaw · updated 2026-10-06 · open in the interactive timeline