Five US federal MCP servers remain vulnerable to unfixed security issues, according to independent researcher Syed Anas Mohiuddin. Among the affected systems is one handling Veterans Affairs benefits claims.

Security teams at Google, JPMorgan Chase, Weaviate, France's interministerial digital directorate (DINUM) and the city government of Tangerang in Indonesia have all patched the same category of vulnerability in their Model Context Protocol (MCP) servers. Mohiuddin disclosed each of these findings in a report released this month.

MCP serves as the standard protocol through which AI agents interact with tools and data sources. The vulnerability in question is server-side request forgery (SSRF). When an MCP server processes a URL, path or endpoint supplied by an agent without validating the destination, it enables an attacker controlling the agent to direct the server toward internal systems or other unintended targets.

Mohiuddin had theorized in May that this flaw represented a systemic issue. His prediction: organizations with entirely separate codebases and ownership structures would independently produce identical vulnerabilities.

Watching the same mistake come back from a hyperscaler, a bank, and a national government, one report at a time, is the moment the May argument stopped being a guess

Syed Anas Mohiuddin

Five fixes

Google's MCP Toolbox for Databases contained an HTTP client lacking both a restrictive redirect policy and validation of target IP addresses, per the GitHub advisory. A malicious path parameter could redirect requests to internal or external endpoints. Designated CVE-2026-14540 with a severity rating of 8.0, the flaw affects versions 0.3.0 through 1.4.0. Google's remediation introduces DNS rebinding protection and configurable IP range allowlists and blocklists, with Mohiuddin credited in the fix.

JPMorgan's open-source codebase includes a documentation-search MCP server featuring two content-fetching tools. One validated domains against an allowlist, while the other retrieved any URL provided by the caller, according to Mohiuddin. The component originated from an AWS project that never performed caller-supplied URL fetches. JPMorgan's Responsible Disclosure team acknowledged the finding and deployed a patch, Mohiuddin reported. He classified the issue as medium severity.

Weaviate confined its Google module's endpoint configuration to Google API hosts exclusively, Mohiuddin noted. DINUM's public MCP server supporting France's open-data infrastructure accepted URLs from data contributors, creating potential access to internal or cloud metadata services. The remediation, labeled "harden SSRF on external APIs", acknowledges "Reported by Syed Anas Mohiuddin".

Tangerang's Wazuh MCP server implemented a tool claiming SSRF protection, yet it only blocked literal IP addresses and never resolved hostnames, according to a high-severity advisory released on 3 September.

Rapid7 addressed a separate vulnerability, CVE-2026-97228, in its Bulk Export MCP server. The flaw permitted GraphQL injection within the operator's own authorization scope, rated low severity at 2.7 according to the database entry.

Still open

On 2 September, Mohiuddin privately disclosed issues affecting five MCP servers operated by the US General Services Administration's Technology Transformation Services. The affected systems support Veterans Affairs benefits claims, CMS Blue Button, regulations.gov, USASpending and CDC PLACES. All five remain in triage without patches applied, Mohiuddin stated.

The Veterans Affairs server logs unredacted error responses from the benefits API, potentially exposing a veteran's name, Social Security number, date of birth and address, according to Mohiuddin. He is withholding technical details until maintainers address the vulnerabilities. His findings regarding Japan's Digital Agency grants server, which lacked authentication entirely, also remain unresolved.

Protocol pivoting

Mohiuddin describes the broader attack methodology as "protocol pivoting". An attacker embeds text within content returned by an MCP tool, formatted as a task for Google's A2A protocol. An orchestrating agent forwards this to a subagent, which executes it based on trust in the orchestrator.

Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch

Douglas McKee, Rapid7's director of vulnerability intelligence

Markus Vervier of X41 D-Sec characterized the technique as a variant of indirect prompt injection. Mohiuddin will present these findings at MCPCon North America in San Jose on 23 October.

Source: The Next Web