В доступных документах результаты проверок и сведения об исправлении есть только в пересказе Ars Technica.
Независимый исследователь Сайед Анас Мохиуддин проверил ИИ-агентов нескольких организаций, включая Google, и показал, как вредоносные инструкции переходят между агентами, которые доверяют друг другу. Ars Technica опубликовала разбор его атак через MCP, протокол подключения ИИ-приложений к внешним инструментам и данным.
Агент получает вредоносную инструкцию из входных данных и передаёт её другому агенту как обычное поручение. Получатель выполняет поручение, поскольку доверяет отправителю.
Атакующий мог заставить инструмент Google для работы с базами данных отправить запрос на внутренний адрес через перенаправление. По данным Ars Technica, Google исправила уязвимость, добавив проверки допустимых и запрещённых IP-адресов.
Проверка утверждений:
- Независимый исследователь Сайед Анас Мохиуддин проверил ИИ-агентов нескольких организаций, включая Google, и показал передачу вредоносных инструкций между агентами, которые доверяют друг другу. (подтверждено только публикацией-переносчиком: доказательство; «In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions. Unexpected and hard to mitigate Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol .»)
- Ars Technica опубликовала разбор атак исследователя через MCP. (подтверждено только публикацией-переносчиком: доказательство; «Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol .»)
- MCP — протокол подключения ИИ-приложений к внешним инструментам и данным. (подтверждено самой публикацией: доказательство; «MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems. Using MCP, AI applications like Claude or ChatGPT can connect to data sources (e.g. local files, databases), tools (e.g. search engines, calculators) and workflows (e.g. specialized prompts)—enabling them to access key information and perform tasks.»)
- Агент получает вредоносную инструкцию из входных данных и передаёт её другому агенту как обычное поручение, а получатель выполняет поручение, поскольку доверяет отправителю. (подтверждено только публикацией-переносчиком: доказательство; «Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work.»)
- Атакующий мог заставить инструмент Google для работы с базами данных отправить запрос на внутренний адрес через перенаправление. (подтверждено только публикацией-переносчиком: доказательство; «The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL either returning an error or redirecting to a different URL. Google’s HTTP client also failed to validate target IP addresses. “A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mohiuddin explained .»)
- По данным Ars Technica, Google исправила уязвимость, добавив проверки допустимых и запрещённых IP-адресов. (подтверждено только публикацией-переносчиком: доказательство; «Google’s fix involved applying an allow-list of IP ranges and block lists.»)
Публикации:
- https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp
- https://modelcontextprotocol.io/docs/2026-07-28/getting-started/intro
оценка 81,6 из 100 · тип: инцидент