<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mcp-Server-Everything (&lt;= 2026.6.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mcp-server-everything--2026.6.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 04:22:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mcp-server-everything--2026.6.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in Model Context Protocol Server Packages</title><link>https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/</link><pubDate>Fri, 02 Oct 2026 04:22:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/</guid><description>A server-side request forgery (SSRF) vulnerability in the Fetch Tool component of the Model Context Protocol server packages allows remote attackers to perform unauthorized requests.</description><content:encoded><![CDATA[<p>A server-side request forgery (SSRF) vulnerability has been identified in the Fetch Tool component within the Model Context Protocol (MCP) packages <code>mcp-server-fetch</code> and <code>mcp-server-everything</code> in versions up to 2026.6.4. The vulnerability resides in the <code>fetch_url</code> function of <code>mcp_server_fetch/server.py</code>. By manipulating the <code>url</code> or <code>path</code> argument, an unauthenticated remote attacker can force the server to perform unauthorized outbound HTTP requests. This could allow an attacker to probe internal network services, access metadata endpoints in cloud environments, or bypass network-level security controls. While the vulnerability has been publicly disclosed and exploitation is possible, a fix is currently pending acceptance via pull request. Defenders should audit applications utilizing these MCP servers for unexpected outbound traffic patterns originating from the server process.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to perform server-side request forgery. This impact may include the exfiltration of sensitive data from internal services, unauthorized access to private cloud metadata services, and reconnaissance of the internal network architecture.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Review applications utilizing <code>mcp-server-fetch</code> or <code>mcp-server-everything</code> for any usage of the Fetch Tool component and verify versioning against the vulnerable range (&lt;= 2026.6.4).</li>
<li>Implement strict egress filtering on the host environment to prevent the MCP server from reaching sensitive internal segments or cloud metadata endpoints.</li>
<li>Monitor web server logs and application logs for unusual URL or path parameters passed to the Fetch Tool's entry points.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>ssrf</category></item></channel></rss>