AIZANOI NEWS

Saturday, 10 October 2026

Technology

Vulnerabilities in MCP agent tooling expose a structural security gap

Security researchers have disclosed flaws in agent-to-agent tooling built on the Model Context Protocol, including a Google MCP Toolbox for databases issue in which an HTTP client was initialised without redirect validation and rated 8.0. A separate Rapid7 flaw, CVE-2026-97228, scored only 2.7 yet still let malicious prompts spread from one agent to another. Ars Technica reported that each protocol checks its own front door while 'nobody watches the hallway in between', a layered-trust problem that is hard to catch whether or not any single component is broken.

By News Desk · Edited by Editorial Desk ·

securitymcpagentsvulnerabilitygoogle

Sources

Ars TechnicaOpenCVE