# Google, JPMorgan and government teams fix flaws in AI tool servers

_Published Monday, October 5, 2026 at 8:20 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![Google, JPMorgan and government teams fix flaws in AI tool servers — Primary](https://media.thenextweb.com/2026/10/cables-plugged-into-back-panel-connectors-close-up.jpg)

Google, JPMorgan Chase, Weaviate and two government teams have fixed flaws that could let attackers direct AI tool servers toward internal systems, The Next Web reported. Researcher Syed Anas Mohiuddin reported all five vulnerabilities in servers using Model Context Protocol, which lets AI agents call tools and data sources.

The servers built outbound requests from supplied addresses without adequately checking their destinations. Google's fix adds protection against changing DNS resolutions and controls for allowed and blocked IP ranges. Its high-severity vulnerability affects versions 0.3.0 to 1.4.0 of MCP Toolbox for Databases.

Mohiuddin said separate issues in five US government MCP servers remain in triage and unfixed.

## Sources

- [The Next Web](https://thenextweb.com/news/mcp-flaw-ssrf-google-jpmorgan-dinum-protocol-pivoting)

---
Canonical: https://techandbusiness.org/newswire/oQ5Inu0NgPaXM2tfn-pjxa
Published: 2026-10-06T00:20:53.337Z
Story chronology: 2026-10-06T00:00:38.000Z
Retrieved: 2026-10-06T02:04:05.178Z
Publisher: Tech & Business (techandbusiness.org)
