SSRF Vulnerability in Model Context Protocol Server Packages
A server-side request forgery (SSRF) vulnerability in the Fetch Tool component of the Model Context Protocol server packages allows remote attackers to perform unauthorized requests.
CVE search metadata
CVE search record: CVE-2026-104120. Severity: high. CVSS: 7.3. KEV: no. Product: mcp-server-fetch (<= 2026.6.4), mcp-server-everything (<= 2026.6.4). Brief: SSRF Vulnerability in Model Context Protocol Server Packages. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/
A server-side request forgery (SSRF) vulnerability has been identified in the Fetch Tool component within the Model Context Protocol (MCP) packages mcp-server-fetch and mcp-server-everything in versions up to 2026.6.4. The vulnerability resides in the fetch_url function of mcp_server_fetch/server.py. By manipulating the url or path argument, an unauthenticated remote attacker can force the server to perform unauthorized outbound HTTP requests. This could allow an attacker to probe internal network services, access metadata endpoints in cloud environments, or bypass network-level security controls. While the vulnerability has been publicly disclosed and exploitation is possible, a fix is currently pending acceptance via pull request. Defenders should audit applications utilizing these MCP servers for unexpected outbound traffic patterns originating from the server process.
Impact
Successful exploitation allows remote attackers to perform server-side request forgery. This impact may include the exfiltration of sensitive data from internal services, unauthorized access to private cloud metadata services, and reconnaissance of the internal network architecture.
Recommendation
- Review applications utilizing
mcp-server-fetchormcp-server-everythingfor any usage of the Fetch Tool component and verify versioning against the vulnerable range (<= 2026.6.4). - Implement strict egress filtering on the host environment to prevent the MCP server from reaching sensitive internal segments or cloud metadata endpoints.
- Monitor web server logs and application logs for unusual URL or path parameters passed to the Fetch Tool's entry points.
Immediate actions
Inventory all instances of mcp-server-fetch and mcp-server-everything
Mitigations
Restrict egress traffic from MCP server hosts to sensitive internal/cloud IP ranges
CVE-2026-104120