# A researcher reports the same request-forgery pattern in MCP servers at Google, JPMorgan and several governments

> Independent researcher Syed Anas Mohiuddin says MCP servers build requests from agent-supplied URLs and log full upstream responses. Google fixed CVE-2026-14540.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-06
Canonical: https://hisnlabs.com/en/news/mcp-servers-ssrf-protocol-pivoting-google-jpmorgan-governments

Unite.AI reported on 5 October 2026 that independent researcher Syed Anas Mohiuddin has documented one flaw pattern in Model Context Protocol (MCP) servers run by Google, JPMorgan Chase and government bodies in several countries [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). The pattern is server-side request forgery combined with unsafe handling of upstream data. MCP servers are the tool servers that AI agents call, and many run on developers’ own Macs.

## Background

An MCP server exposes tools to an agent, such as a documentation search or an API client. When the server builds an outbound request from an address the agent supplies, an agent steered by a hostile prompt can point the server at internal or arbitrary endpoints. Unite.AI says Mohiuddin published a preprint on the topic, “Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems”, on 24 May 2026 [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/).

## Findings

According to the report, the root cause is that MCP servers build outbound requests from agent-supplied URLs without validation, and write complete upstream API responses to central logs without redaction [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). The affected servers listed include Google’s mcp-toolbox, versions 0.3.0 to 1.4.0, tracked as CVE-2026-14540 with a score of 8.0 (High) and fixed in version 1.5.0; a documentation-search server in JPMorgan’s ai repository, rated Medium and fixed; and servers belonging to France’s DINUM, a municipal government in Indonesia and Japan’s Digital Agency [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/).

The report says five findings against United States federal servers were filed as private advisories on 2 September 2026 and were still in triage and unfixed at the time of writing, and that a pull request for the Japanese server was open and unmerged [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). For one benefits-claims server, it states that routine validation failures wrote full upstream error bodies containing names, Social Security numbers, dates of birth and addresses to logs; code-level details were withheld pending patches [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/).

Google’s fix adds an SSRF guard against DNS rebinding, configurable allowlists for private networks and address ranges, and validation of the base URL at start-up [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). Mohiuddin also released mcp-safeguard, an open-source scanner covering six classes: request forgery, excessive permissions, prompt injection, information leakage, authentication gaps and lifecycle bypass [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). Startup Fortune, summarising earlier research, reports that OX Security estimated about 200,000 vulnerable instances through MCP’s STDIO transport and that Knostic found none of 1,862 internet-exposed MCP servers it scanned performed authentication checks [[2]](https://startupfortune.com/security-researchers-say-anthropics-mcp-protocol-puts-200000-servers-at-risk/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, shows which app opens each connection and lets you block a destination for that app. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

Most of the named servers run in organisations, so the direct exposure is institutional. For a developer who runs MCP servers locally, the pattern still applies: a tool server that fetches whatever address an agent hands it can reach services on the home or office network and can store sensitive responses in its logs. A prompt injection that steers the agent is enough to trigger the request.

## Recommendations

1. Update MCP servers and libraries you run, for example mcp-toolbox to version 1.5.0 or later.
2. Prefer servers that validate outbound URLs and restrict private network ranges.
3. Check where a tool server writes logs, and avoid logging full upstream responses that may hold personal data.
4. Run local MCP servers with the fewest credentials and folders they need.
5. Review which destinations your agents and their tool servers contact, and investigate any that are new.

## Relevance to FireAI

FireAI is a firewall for one Mac. The [Agent profile](https://hisnlabs.com/en/docs/agent-profile) recognises 19 AI agents and the child processes they start, learns for the first 3 days which destinations each normally contacts, and flags a new destination or an upload spike, using only host names and byte counts. [Per-app rules](https://hisnlabs.com/en/docs/per-app-rules) allow blocking a destination for one app.

FireAI does not scan MCP servers, does not validate their requests and does not patch them. It does not read what a tool server logs, and it does not read the inside of an encrypted connection. It cannot fix a server run by a third party.

> When an agent’s tool server reaches somewhere new, a firewall can ask first. FireAI keeps a per-app record of connections on the Mac. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The central account rests on one outlet, Unite.AI, which summarises the researcher’s disclosures; Ars Technica published related coverage, but it could not be fetched, so it is not used here [[1]](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/). The Startup Fortune page describes other research and is cited only for context [[2]](https://startupfortune.com/security-researchers-say-anthropics-mcp-protocol-puts-200000-servers-at-risk/). The report’s table gives several fix dates, and this item has not verified the advisories or the CVSS score against the vendors’ own pages.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Unite.AI, 5 October 2026: Researcher discloses same MCP flaw at Google, JPMorgan, two governments](https://www.unite.ai/researcher-discloses-same-mcp-flaw-at-google-jpmorgan-two-governments/)
- [Startup Fortune, October 2026: Security researchers say Anthropic’s MCP protocol puts 200,000 servers at risk (context)](https://startupfortune.com/security-researchers-say-anthropics-mcp-protocol-puts-200000-servers-at-risk/)
