{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/get-html-skeleton/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-81093"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["get-html-skeleton"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","cloud-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe get-html-skeleton tool is vulnerable to Server-Side Request Forgery (SSRF) due to improper URL validation logic within the \u003ccode\u003esrc/tools/common/get_html_skeleton.ts\u003c/code\u003e file. The validation mechanism, implemented via \u003ccode\u003eisValidHttpUrl\u003c/code\u003e in \u003ccode\u003esrc/utils/generic.ts\u003c/code\u003e, performs only superficial syntax checks - confirming the presence of an 'http' or 'https' scheme - without assessing the destination hostname or the resolved IP address.\u003c/p\u003e\n\u003cp\u003eThis failure enables an attacker to provide URLs targeting sensitive internal infrastructure, including loopback (127.0.0.1), link-local (169.254.169.254), and private IP address ranges. Because the tool subsequently processes the fetch request and returns the resulting document content to the caller, an attacker can leverage this primitive to access protected cloud instance metadata services or other internal resources reachable from the server's network context. This vulnerability is addressed in version 0.9.12, which removes the tool entirely.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an unauthenticated attacker to bypass network boundary controls and exfiltrate sensitive data, including cloud instance credentials, environment configuration, and other internal documents that are not exposed to the public internet but are accessible from the host environment. This represents a significant risk for cloud-native deployments where metadata services are frequently used to manage identity and access rights.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the relevant MCP server environment to version 0.9.12 or newer to remove the vulnerable get-html-skeleton tool.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious internal-range requests if the affected service is exposed to untrusted users or network segments.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering or network segmentation to restrict the server from accessing sensitive local services like the AWS, GCP, or Azure metadata endpoints (e.g., 169.254.169.254).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T19:10:19Z","date_published":"2026-08-27T19:10:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-81093/","summary":"The get-html-skeleton tool contains an SSRF vulnerability via insufficient URL validation, allowing remote callers to exfiltrate cloud instance metadata or internal credentials.","title":"SSRF Vulnerability in get-html-skeleton MCP Tool","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-81093/"}],"language":"en","title":"CraftedSignal Threat Feed - Get-Html-Skeleton","version":"https://jsonfeed.org/version/1.1"}