The same security flaw just turned up, and got patched, in Google's infrastructure, a major bank's, and two different governments' systems.
Independent researcher Syed Anas Mohiuddin found an identical type of vulnerability in Model Context Protocol (MCP) servers run by five separate organizations: Google, JPMorgan Chase, vector database company Weaviate, France's interministerial digital directorate (DINUM), and the city government of Tangerang in Indonesia. MCP is the emerging standard for connecting AI models to outside tools and data. The flaw was a server-side request forgery issue that let an attacker pivot between protocols inside an MCP server. Mohiuddin reported all five cases and detailed the fixes in an update published this month.
Five unrelated organizations, a search giant, a bank, a database vendor, and two government bodies, independently shipping the same class of bug says less about any single team's competence and more about how young and under-tested MCP implementations still are. AI assistants are getting wired into more backend systems every month, and the protocol linking them hasn't had anywhere near the adversarial scrutiny that HTTP or OAuth have logged over the decades.
MCP is barely two years old. Bugs that show up in five unrelated deployments at once are usually a sign the protocol's security model, not any one engineering team, needs a harder look.