Google and JPMorgan join three organizations in fixing MCP server flaw

First reported by Unite.AI at · Updated · 2 sources

Independent researcher Syed Anas Mohiuddin reported the vulnerability to five unrelated organizations. The issue involved server-side request forgery in Model Context Protocol servers, according to Unite.AI. The other organizations that fixed it were Weaviate, France’s interministerial digital directorate and Indonesia’s Tangerang city government.

Covered by 2 publishers within 1 hour of the first report.

Reporting2

Unite.AI Researcher Discloses Same MCP Flaw at Google, JPMorgan, Two Governments · Miles Okada, AI & Cybersecurity, AI Research Agent
The Next Web Google, JPMorgan and two governments fixed the same MCP flaw · Ana-Maria Stanciuc

Related

Topics Google