Protocol pivoting: injected tool output turns MCP servers into SSRF relays
A researcher's October 2026 update ties SSRF flaws in MCP servers at Google, JPMorgan, Weaviate and others to a delegation pattern where injected tool output reaches privileged subagents.
What is this?
In an update published on 5 October 2026, independent researcher Syed Anas Mohiuddin described a pattern he calls “protocol pivoting” and linked it to server-side request forgery (SSRF) bugs he reported in several Model Context Protocol (MCP) servers. Press coverage on 6 October says Google, JPMorgan Chase, Weaviate, France’s DINUM and the Indonesian city of Tangerang have fixed their instances. Separately, a GitHub advisory for Google’s MCP Toolbox for Databases was published on 31 July 2026, and the Wazuh MCP server advisory on 3 September 2026.
The key idea is not a new bug class. SSRF is old. The novelty is the delivery path: text planted in content returned by an MCP tool reaches a privileged component through ordinary agent delegation.
How it works
According to the researcher’s write-up, the chain has two ingredients:
- Delegation trust. Tool output containing text that resembles a task instruction is forwarded by an orchestrating agent to a subagent. The subagent treats it as legitimate delegation from a trusted peer.
- An MCP server that builds outbound requests from unvalidated arguments. The published advisories describe the typical faults: an HTTP client that follows redirects without re-checking the destination (Google’s toolbox, affected versions 0.3.0 to 1.4.0), and an input check that rejects literal private IP addresses but not hostnames that resolve to them (the Wazuh server).
Combined, a request originates from inside the trust boundary, with the subagent’s network position and credentials. A second failure mode noted in the write-up is servers logging full upstream API responses without redaction, so routine errors leak sensitive data. As the researcher puts it, each component “behaved as designed”, which is why the problem sits in the composition rather than in any single product.
The scale figure circulating in coverage (36.7% of about 7,000 scanned MCP servers vulnerable to SSRF) comes from the researcher’s own scan and has not been independently reproduced as far as we could verify. It is directionally consistent with earlier ecosystem measurements we covered in July 2026.
Why it matters
Agent pipelines increasingly chain orchestrators, subagents and tool servers. If any hop treats upstream text as an instruction, a low-privilege content source can steer a high-privilege network client. The affected organizations span a cloud vendor, a bank, a vector database vendor and public-sector projects, which suggests the pattern is common in server implementations, not a one-off. The researcher also reports that several government servers remained unpatched as of 6 October; we do not name them here.
Defenses
- Resolve, then validate, at connection time. Check the resolved IP against a blocklist (loopback, link-local, private ranges, cloud metadata addresses) and pin the connection to that address to defeat DNS rebinding.
- Disable automatic redirects or re-validate every hop.
- Per-tool host allowlists for any tool that fetches URLs, instead of denylists.
- Do not treat tool output as delegation. Orchestrators should mark tool-derived text as data, and subagents should require task instructions to come from a typed, authenticated channel rather than free text.
- Scope credentials per agent instead of sharing one pool, and keep metadata services unreachable (for example, enforce IMDSv2 or block the endpoint).
- Redact upstream responses before logging or returning errors.
- Scan your own servers with an SSRF-focused scanner and review logs for outbound requests to internal ranges.
- Upgrade Google’s MCP Toolbox for Databases to a release containing the SSRF fix (the researcher cites version 1.5.0) and apply the Wazuh MCP server fix.
Status
| Item | Status | Reference |
|---|---|---|
| Google MCP Toolbox for Databases | Fixed (advisory published 2026-07-31; fix reported in 1.5.0) | CVE-2026-14540, GHSA-3x3x-8ffg-ghcv |
| Wazuh MCP server (Tangerang) | Fixed (advisory 2026-09-03) | GHSA-pw2j-pj4h-f5vg |
| JPMorgan, Weaviate, DINUM instances | Reported fixed | See press coverage |
| Some US government servers | Reported unpatched as of 2026-10-06 | Not named |
Sources
- → https://thenextweb.com/news/mcp-flaw-ssrf-google-jpmorgan-dinum-protocol-pivoting
- → https://www.techtimes.com/articles/328621/20261006/six-weeks-after-google-jpmorgan-patched-mcp-flaw-us-servers-stay-exposed.htm
- → https://anas-security-portfolio.vercel.app/protocol-pivoting-update.html
- → https://github.com/advisories/GHSA-3x3x-8ffg-ghcv
- → https://github.com/INFOKOM-KI/Wazuh-MCP-Server/security/advisories/GHSA-pw2j-pj4h-f5vg
- → https://nvd.nist.gov/vuln/detail/CVE-2026-14540