Attackers can exploit trust between AI agents to spread malicious instructions and force systems to access closed services. This was reported by Qazaqyia.kz citing Kursiv Media.
Such a scenario was described by independent security researcher Syed Anas Mohiuddin, Ars Technica reports.
What are AI agents?
AI agents are programs that can perform tasks using external tools, for example searching for information or working with databases. The MCP protocol is used to connect such tools.
How does the attack begin?
An attack can start with a malicious instruction hidden in a document or other material. One agent reads it and passes it to another as a routine work task. The second trusts the first and executes the attacker's command.
If the connected tool is poorly protected, this can force the server to access the company's closed resources. As a result, there is a risk of access to internal services and confidential data.
Which projects had vulnerabilities?
According to Mohiuddin, similar vulnerabilities were confirmed and fixed in projects by Google, JPMorgan Chase, Weaviate, the French digital service DINUM and the administration of the Indonesian city of Tangerang.
The researcher also reported possible problems in five systems for US federal agencies. At the time his report was published, these reports were still being verified.
The most serious flaw
One of the most serious flaws was found in Google's database tool. Its severity was rated 8 out of 10. The server could follow substituted addresses and send requests to internal resources. Google fixed the problem by adding address checks and access restrictions.
In a tool from Rapid7, another flaw was found: unverified data allowed requests to the service to be changed. It was rated 2.7 out of 10 and was also fixed. At the same time, the flaw did not grant access beyond the rights of the account being used.
The researcher's recommendations
The researcher recommends verifying AI agent requests and limiting tools' access to internal resources. Even if a command is passed by another program inside the company, that does not mean it is safe.
