Today for AI

Ars Technica AI · 2026/10/5 22:26:35

MCP 协议现跨智能体注入漏洞,安全专家警示风险

出处作者 / 发布主体:Dan Goodin原标题:MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
78AI 研判分
核心综述

独立研究员发现 Model Context Protocol (MCP) 存在严重安全隐患,攻击者可利用智能体间的信任机制实施“跨智能体提示注入”。该漏洞允许恶意指令在内部网络中通过一个被攻陷的智能体传播至其他智能体,导致数据泄露等后果。目前 Google、摩根大通等多家机构已确认相关脆弱性,凸显了多智能体协作架构中的信任边界缺失问题。

报道全文原始报道全文

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.

In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.

Unexpected and hard to mitigate

Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.