A report published October 5, 2026, described proof-of-concept work by security researcher Syed Anas Mohiuddin in which malicious content read by one AI agent could be passed to another as an ordinary delegated task. If the second agent trusts the sender, it may act on the instruction. The mechanism sits alongside two separate software flaws: an SSRF vulnerability in Google MCP Toolbox for Databases and GraphQL query injection in Rapid7 Bulk Export MCP.
How a malicious instruction can pass between agents
The Model Context Protocol (MCP) lets AI applications and agents communicate with tools and other agents. In the reported proof of concept, hostile text enters content an agent reads, then travels onward as a delegated task. The next agent may treat that task as trusted because it came from another agent.
Mohiuddin calls the multi-protocol pattern “protocol pivoting.” The practical concern is the handoff: an instruction can cross an agent trust boundary while appearing to be a routine task.
Two vulnerabilities, two different failure modes
The Google and Rapid7 cases affect different products and involve different vulnerability types. Google’s CVE-2026-14540 is server-side request forgery (SSRF), in which a server can be induced to send requests to other endpoints. Rapid7’s CVE-2026-97228 is GraphQL query injection.
| Product | CVE | Flaw type | Affected versions | How the flaw worked |
| Google MCP Toolbox for Databases | CVE-2026-14540 | SSRF | 0.3.0 through 1.4.0 | Unsafe redirect handling and missing destination-IP validation could let a crafted path parameter trigger server-side requests to internal or external endpoints. |
| Rapid7 Bulk Export MCP | CVE-2026-97228 | GraphQL query injection | 0.2.5 through 0.6.1 | An unvalidated export_id was interpolated into a GraphQL query. |
Rapid7 identifies version 0.6.2 as the fix for its issue. Its record also says the flaw did not cross tenant or account boundaries or grant access beyond the operator’s existing authenticated API scope.
What Google’s fix addresses
The Google vulnerability involved HTTP requests that could follow unsafe redirects without checking whether the destination IP address was permitted. In an October 2026 account, Mohiuddin described the remediation as validating resolved addresses when connecting, applying IP-range allow and block lists, and rejecting unsafe base URLs at startup. NVD’s record identifies Google MCP Toolbox versions 0.3.0 through 1.4.0 as affected by CVE-2026-14540.
Authorization is the critical boundary
A sandbox can limit an agent’s access to the host, but it does not by itself remove permissions to use tools or network access the agent already has. That makes authorization around tool actions important: content passed to a tool or through a delegated task should be treated as untrusted, and sensitive operations should require authorization before the agent acts.