In an October 2026 research update titled "Protocol Pivoting, four months later," independent researcher Syed Anas Mohiuddin reports that an identical server-side request forgery mistake in Model Context Protocol servers has been confirmed and fixed by security teams at five organisations with no shared code, industry, country, or owner: Google, JPMorgan Chase, Weaviate, France's interministerial digital directorate, and the Tangerang City government in Indonesia. unite.ai carries the full list.
Ars Technica's reporting covers the same window: over the past five months, Google and four other organizations have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets a particular agent — a translation agent, a data-analysis agent — rather than the underlying LLM. Two outlets, one disclosure set, no shared codebase among the vendors involved.
The list itself carries the argument. A search company, a bank, a vector-database vendor, a French state digital directorate and an Indonesian city government do not share suppliers, regulators or threat models. What they share is MCP. When an identical server-side request forgery mistake appears in five independently written servers, the reasonable reading — and the one Mohiuddin's update draws — is that the defect sits in a pattern the protocol invites, not in five separate lapses.
In May 2026, Mohiuddin made a prediction with a clear failure condition: if the weakness were structural rather than a single careless implementation, the same bug would surface in servers written by teams sharing no code, industry, country, or owner. The October update, titled "Protocol Pivoting, four months later," runs the test. The prediction named the distribution of the defect, not the organisations, which is what makes the outcome legible.
The result is five confirmations across four months. Each security team independently found and fixed the same mistake in its own server, which is the exact outcome the structural hypothesis predicted and the single-implementation hypothesis ruled out. That suggests the flaw travels with how MCP servers are commonly built rather than with any one team's competence. A prediction that survives contact with five unrelated codebases stops being a hunch and starts being a finding.
The wider ecosystem is already building around the problem. The changelog for Grok Build, version 1.0.46, dated September 30, 2026, records that "grok inspect and the MCP doctor report MCP server sources correctly" — tooling for auditing which MCP servers an agent actually loads. When CLI vendors ship provenance reporting for protocol servers, that suggests operators have begun treating server identity as a security question rather than a configuration detail. x.ai published the entry.
The stakes come from scale. Ars Technica notes that the adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. The publication's framing is blunt: MCP for agent-to-agent communications may be the riskiest protocol you have never heard of. Millions of deployments plus one structural defect is a multiplication problem.
The pivot mechanism changes where defences belong. Because the injection targets a specific internal agent and uses it to spread instructions to other internal agents, a hardened model or a filtered prompt is insufficient; the compromised agent is the delivery channel. That suggests per-agent guardrails are the wrong perimeter for MCP deployments, and that the unit of defence has to be the protocol hop between agents, not the agent itself.
The record leaves gaps worth naming. Neither disclosure specifies severity scores, exploit chains or bounty amounts, and neither states whether the five fixes change server implementations or the protocol specification itself — that distinction determines whether the same bug can surface a sixth time. What the record does establish is a pattern with a testable prediction behind it, five independent confirmations, and a fix cycle completed at every organisation named.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.