Case file · Security research ● Active, Sep 2026

Vulnerability disclosure record

Anas Mohiuddin

I find security holes in the plumbing that lets AI assistants use outside tools, report them, and build the tools that check for the same problems automatically

Verified19+confirmed fixes

Google, Apache, dbt Labs, Weaviate and Norway's national labour agency have all confirmed and fixed security bugs I reported this year, out of about 280 reports I've sent. I also built a free scanner that checks for the same kinds of problems automatically, and I've had fixes merged straight into GitHub's and MongoDB's own official MCP servers.

MCP is the plug that lets an AI assistant read your files, call your APIs, or browse the web on your behalf. When that plug is wired wrong, the assistant can be tricked into leaking secrets or reaching servers it should never touch. That's the wiring I spend my time checking.

~280 reports I've sent this year
19+ confirmed and fixed, with credit
8 security teams currently reviewing active reports

What I found

Each one: what the system was supposed to do, what it actually let through, and what happened once I reported it.

Google
·

Google's MCP Toolbox for Databases is supposed to only reach out to data sources it's been given permission to reach.

−

I found a way to make it reach out to any address on the internet instead, including private ones it should never have been able to touch.

+

Google confirmed it, fixed it, and credited the finding by name.

Confirmed & fixed CVE‑2026‑14540 Fix PR, credited by name May 2026
Apache Software Foundation
·

Apache's IoTDB MCP server is supposed to only run commands it's been explicitly told to trust.

−

I found a way around that check.

+

Their team confirmed it, merged a fix within two days, and credited the report.

Confirmed & fixed iotdb‑mcp‑server PR #19 Sep 2026
dbt Labs
·

The dbt MCP server is supposed to check user input before acting on it.

−

I found a way that input could slip through unchecked.

+

dbt Labs reproduced the issue, shipped a fix, and closed the report.

Confirmed & fixed dbt‑mcp PR #874
WWeaviate
·

A setting in Weaviate's Google integration is supposed to keep requests going only to Google.

−

I found a way to use that setting to redirect the request and pull credentials along with it.

+

Weaviate fixed it and added the finding to their public Hall of Fame.

Confirmed & fixed HackerOne #3968010
NAVNAV · Norwegian government labour & welfare agency
·

A tool NAV relies on is supposed to keep its access limited the way it claims.

−

I reported a vulnerability that broke that assumption.

+

Their security team confirmed it in plain terms, and a fix followed days later.

Confirmed & fixed GHSA‑7hwf‑488h‑59x8
AOSarifOS
·

arifOS's agent tools are supposed to only touch the database queries and file paths they're explicitly given.

−

I found an SSRF in its fetch tool, then came back and found three more: a Cypher injection, a path traversal, and a webhook signature that accepted forged requests.

+

The maintainer fixed the SSRF and filed a CVE for it, then confirmed and shipped fixes for all three follow-up findings the same week.

Confirmed & fixed fix commit c8e8670 CVE pending (MITRE CAN‑2026‑2037739)
Snyk
·

Snyk's agent-scan tool is supposed to ask before it goes and contacts an outside web address.

−

I found a way to make it contact any remote MCP server address with no permission check first.

+

Snyk's team reproduced it and passed it to engineering. Fix in progress.

Confirmed, fix in progress SNYK‑ZB3JICBM Sep 2026
+

And I fix them too. Found and patched a bug directly in GitHub's own official MCP server, not just reported it. Merged.

+

Same with MongoDB. Patched a bug directly in MongoDB's own official MCP server. Merged.

The scanner

A free, open-source tool that checks for the same kinds of problems automatically, instead of waiting for someone to find them by hand.

mcp-safeguard scans an MCP server for 52 specific problems: instructions hidden inside content that try to trick the AI, passwords or keys left somewhere they shouldn't be, tools that can be tricked into reaching servers they have no business reaching, and tools that quietly change what they do after they've already been approved.

$ pip install mcp-safeguard

Recognized by

Beyond the flagship reports above, more advisories carrying my name, and a control I helped standardize.

OWASP MCP Top 10. Submitted a control for detecting and preventing SSRF in MCP fetch and scrape tools, the same class of bug behind the Google finding above. Open for review with the project maintainers.

Open, under review OWASP PR #42
+DollhouseMCPGHSA‑x8w3
+ark‑forgeGHSA‑93f9
+jupyter‑mcp‑serverGHSA‑f8rf
+code‑graph‑ragGHSA‑wvxg
+pluggedin‑appGHSA‑m623
+powershell‑mcpGHSA‑mf4q
+mcp‑video‑analyzerGHSA‑hpmc
+Repliers‑ioPR #14
+warpfreightGHSA‑7cc5
+1Password‑MCPGHSA‑q3gg

Writing

Explaining the same findings in plain language, for people who don't read advisories for fun.

"I found an SSRF in Google's official MCP Toolbox": CVE-2026-14540, and why standard dependency scanners can't see this bug class at all.read it
"Never Emitted": GitHub asks for credit, displays it, and leaves it out of the machine-readable CVE record. 0 of 570 in a full census.read it
"I built the first security scanner for MCP servers, here's what I found"dev.to · link pending confirmation
"The security problem nobody is talking about: MCP servers"dev.to · link pending confirmation

Currently under review

Reports that have gotten a real response from a human on the security team and are actively being worked, not just an autoresponder.

IBM Juniper Networks HashiCorp Datadog Splunk Okta Grafana