{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mcp-server-fetch--2026.6.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*","cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-104120"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-server-fetch (\u003c= 2026.6.4)","mcp-server-everything (\u003c= 2026.6.4)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf"],"_cs_type":"advisory","_cs_vendors":["modelcontextprotocol"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability has been identified in the Fetch Tool component within the Model Context Protocol (MCP) packages \u003ccode\u003emcp-server-fetch\u003c/code\u003e and \u003ccode\u003emcp-server-everything\u003c/code\u003e in versions up to 2026.6.4. The vulnerability resides in the \u003ccode\u003efetch_url\u003c/code\u003e function of \u003ccode\u003emcp_server_fetch/server.py\u003c/code\u003e. By manipulating the \u003ccode\u003eurl\u003c/code\u003e or \u003ccode\u003epath\u003c/code\u003e argument, an unauthenticated remote attacker can force the server to perform unauthorized outbound HTTP requests. This could allow an attacker to probe internal network services, access metadata endpoints in cloud environments, or bypass network-level security controls. While the vulnerability has been publicly disclosed and exploitation is possible, a fix is currently pending acceptance via pull request. Defenders should audit applications utilizing these MCP servers for unexpected outbound traffic patterns originating from the server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to perform server-side request forgery. This impact may include the exfiltration of sensitive data from internal services, unauthorized access to private cloud metadata services, and reconnaissance of the internal network architecture.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview applications utilizing \u003ccode\u003emcp-server-fetch\u003c/code\u003e or \u003ccode\u003emcp-server-everything\u003c/code\u003e for any usage of the Fetch Tool component and verify versioning against the vulnerable range (\u0026lt;= 2026.6.4).\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the host environment to prevent the MCP server from reaching sensitive internal segments or cloud metadata endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs and application logs for unusual URL or path parameters passed to the Fetch Tool's entry points.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T04:22:17Z","date_published":"2026-10-02T04:22:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/","summary":"A server-side request forgery (SSRF) vulnerability in the Fetch Tool component of the Model Context Protocol server packages allows remote attackers to perform unauthorized requests.","title":"SSRF Vulnerability in Model Context Protocol Server Packages","url":"https://feed.craftedsignal.io/briefs/2026-10-mcp-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Mcp-Server-Fetch (\u003c= 2026.6.4)","version":"https://jsonfeed.org/version/1.1"}