Five unrelated teams shipped the same MCP bug. That's not a coincidence.
Researcher Syed Anas Mohiuddin found the same SSRF flaw at Google, JPMorgan, a French agency, Weaviate and an Indonesian city government. The spec has no normative security requirements, and every agent inside the network is implicitly trusted by the rest.
Plant a prompt injection in one dumb translation agent and it hops down the chain. Five US government servers are still unpatched after six weeks.
Post #670
162