
The plumbing that connects AI agents to the outside world is showing cracks. On October 5, 2026 (UTC), independent security researcher Syed Anas Mohiuddin published an update showing that the same server-side request forgery (SSRF) vulnerability in Model Context Protocol (MCP) servers has been confirmed and patched at five unrelated organizations: Google, JPMorgan Chase, Weaviate, France's interministerial digital directorate, and the Tangerang City government in Indonesia. The findings are the latest in a growing string of security issues affecting MCP, the protocol Anthropic released in November 2024 that has become the default plumbing for coding assistants and enterprise agent stacks.
What's actually broken
MCP is the "USB-C port" of AI agents — a standardized way for models to connect to tools, databases, filesystems, and other agents. That ubiquity is exactly what makes its security flaws so consequential. When a protocol becomes infrastructure, a single pattern of mistake can show up everywhere.
The SSRF pattern Mohiuddin documented is straightforward: MCP servers that fetch URLs on behalf of an agent often fail to restrict where those requests can go. A malicious or compromised server can pivot from fetching a public webpage to probing internal services — cloud metadata endpoints, internal APIs, database admin panels — turning the agent's tool access into a network tunnel. The fact that the same class of bug appeared at Google, a major bank, a vector database startup, and two government agencies suggests this isn't a one-off coding error. It's a design-level assumption that MCP servers can trust the URLs they're given.
The NVD took the issue seriously enough to assign CVE-2026-104120 on October 2, 2026 (UTC), affecting the official reference servers mcp-server-fetch and mcp-server-everything up to version 2026.6.4. The vulnerability sits in the fetch_url function and is exploitable remotely. At the time of disclosure, the fix was a pull request awaiting acceptance — meaning the official reference implementation was shipping the bug.
Separate research from the Cloud Security Alliance, published September 30, 2026 (UTC), documented a CVSS 7.5 flaw in the official MCP Python SDK where a malicious MCP server could redirect a connecting client's OAuth client secret, authorization code, and PKCE proof key to an attacker-controlled endpoint, enabling full account takeover of the downstream identity provider session. The root cause was a missing issuer-validation step on a legacy fallback discovery endpoint.
OX Security estimated in April 2026 that roughly 200,000 MCP servers were exposed to a related STDIO transport flaw. That number has almost certainly grown as enterprise adoption accelerates.
Why it matters
The MCP security story is a textbook example of what happens when a protocol wins before it's hardened. Anthropic released MCP in late 2024 as an open standard, and adoption exploded because it solved a real problem — agents needed a uniform way to call tools. But the protocol was designed for a world where MCP servers were local, trusted, and few in number. The reality in 2026 is that MCP servers are remote, unvetted, and number in the hundreds of thousands.
The pattern of vulnerabilities is revealing. SSRF in fetch servers. OAuth redirect flaws in SDKs. Redirect following in HTTP transports. These aren't exotic zero-days — they're the same class of web security bugs the industry spent fifteen years learning to prevent. MCP reintroduced them because the protocol's reference implementations prioritized functionality over input validation, and the ecosystem copied those implementations.
The organizational spread is the real warning sign. Google and JPMorgan have among the most mature application security programs on the planet. If the same SSRF pattern slipped through both of them, it's almost certainly present in thousands of less-resourced organizations. The French and Indonesian government confirmations show the issue isn't limited to tech companies — it's already in public sector infrastructure.
There's a deeper concern. MCP is designed to give agents execution capability. When an MCP server is compromised, the attacker doesn't just get data — they get a channel to influence the agent's behavior. A compromised server can return poisoned tool results, steer the agent toward malicious actions, or use the agent's permissions as a pivot point into other systems. In an agentic world where models are increasingly autonomous, that's a supply chain attack with teeth.
What to watch
- Whether the MCP working group publishes a formal security review of the protocol specification, or whether fixes remain scattered across individual SDK and server repositories
- How quickly enterprise MCP deployments audit for the SSRF and OAuth patterns — the gap between CVE publication and actual patching is where incidents happen
- Whether major MCP clients (Claude Desktop, Cursor, ChatGPT) add server-side validation or sandboxing to limit the blast radius of a compromised server
- Whether governments issue formal guidance on MCP deployment, given that French and Indonesian agencies have already been affected
- Whether the 200,000-server estimate from OX Security gets updated, and whether any of those exposures lead to confirmed data breaches
MCP isn't going away — it's too useful and too widely adopted. But the protocol is entering the phase where its security maturity has to catch up to its deployment footprint. The organizations that treat this as a plumbing problem rather than an agent problem will be the ones reading about incidents instead of experiencing them.
No comments yet