Skip to content
Threat Feed
high advisory

SSRF Vulnerability in Model Context Protocol Server Packages

A server-side request forgery (SSRF) vulnerability in the Fetch Tool component of the Model Context Protocol server packages allows remote attackers to perform unauthorized requests.

CVE search metadata

CVE search record: CVE-2026-104120. Severity: high. CVSS: 7.3. KEV: no. Product: mcp-server-fetch (<= 2026.6.4), mcp-server-everything (<= 2026.6.4). Brief: SSRF Vulnerability in Model Context Protocol Server Packages. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/

A server-side request forgery (SSRF) vulnerability has been identified in the Fetch Tool component within the Model Context Protocol (MCP) packages mcp-server-fetch and mcp-server-everything in versions up to 2026.6.4. The vulnerability resides in the fetch_url function of mcp_server_fetch/server.py. By manipulating the url or path argument, an unauthenticated remote attacker can force the server to perform unauthorized outbound HTTP requests. This could allow an attacker to probe internal network services, access metadata endpoints in cloud environments, or bypass network-level security controls. While the vulnerability has been publicly disclosed and exploitation is possible, a fix is currently pending acceptance via pull request. Defenders should audit applications utilizing these MCP servers for unexpected outbound traffic patterns originating from the server process.

Impact

Successful exploitation allows remote attackers to perform server-side request forgery. This impact may include the exfiltration of sensitive data from internal services, unauthorized access to private cloud metadata services, and reconnaissance of the internal network architecture.

Recommendation

  1. Review applications utilizing mcp-server-fetch or mcp-server-everything for any usage of the Fetch Tool component and verify versioning against the vulnerable range (<= 2026.6.4).
  2. Implement strict egress filtering on the host environment to prevent the MCP server from reaching sensitive internal segments or cloud metadata endpoints.
  3. Monitor web server logs and application logs for unusual URL or path parameters passed to the Fetch Tool's entry points.

Immediate actions

Inventory all instances of mcp-server-fetch and mcp-server-everything

IT Operations 24h

Mitigations

Restrict egress traffic from MCP server hosts to sensitive internal/cloud IP ranges

immediate IT Operations

CVE-2026-104120