
MCP Security Risks Grow as AI Agents Start Trusting Other Agents A newly examined set of vulnerabilities shows why AI-agent security becomes harder when one system starts trusting another. Google's MCP Toolbox for Databases had an SSRF flaw, CVE-2026-14540, rated 8.0 High by Google and fixed through an SSRF guard in version 1.5.0. Rapid7's Bulk Export MCP separately had a low-severity GraphQL query-injection flaw, CVE-2026-97228, fixed in version 0.6.2. These are different implementation bugs, not proof that MCP itself contains one universal vulnerability. The broader concern is how agents, tools and protocols are chained together. Researcher Syed Anas Mohiuddin describes one such cross-protocol pattern as Protocol Pivoting: malicious instructions can enter one agent, pass through MCP tool use or another delegation layer, and reach downstream agents that may inherit too much trust. NSA and Microsoft have separately warned about related risks including prompt injection, unsafe tool chaining and insufficient policy enforcement around agent actions. The security challenge is therefore larger than patching individual CVEs. As multi-agent systems become more interconnected, each trust boundary must be validated rather than assumed. #MCP #AISecurity
