Sceawere

Vulnerability Detail

CVE-2026-104120UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF in mcp-server-fetch Tool

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
20h ago
Vendor
modelcontextprotocol
Product
mcp-server-fetch
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-02T03:16:38.840Z",
  "pubdate": "2026-10-02T03:16:38.840Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the fetch_url function within the Fetch Tool component of mcp-server-fetch and mcp-server-everything versions up to 2026.6.4.\nThe vulnerability allows a remote, unauthenticated attacker to manipulate the URL or path arguments to force the server to perform unauthorized requests to arbitrary internal or external resources.\nThe primary impact includes unauthorized access to internal network services, information disclosure of sensitive configuration data, and potential exploitation of internal infrastructure that trusts the hosting environment.\nThis flaw is remotely exploitable, requiring no prior authentication or specific privilege level to initiate, as the Fetch Tool is designed to process user-provided inputs to retrieve external content.\nThe public disclosure of the exploit increases the risk of active abuse, necessitating immediate remediation once a verified patch is available.",
  "technicalDetails": "The vulnerability resides in the mcp_server_fetch/server.py file, specifically within the fetch_url function. The implementation lacks robust input validation and sanitization for the url/path parameters passed to the network request mechanism.\nRoot cause analysis indicates that the application fails to enforce a whitelist or validation policy on the target destination of the fetch request. By failing to restrict the protocol, host, or port of the requested resource, the application permits a malicious actor to supply arbitrary URLs.\nThe attack flow begins when an attacker invokes the Fetch Tool via the Model Context Protocol (MCP) interface with a crafted payload. Instead of pointing the tool toward a legitimate, expected resource, the attacker specifies an internal address or a local loopback interface (e.g., http://127.0.0.1:port or http://169.254.169.254/latest/meta-data/).\nUpon receiving the malicious input, the server initiates an outbound request from the server-side environment to the targeted URI. The server-side context allows the attacker to bypass network boundary protections and firewalls that would otherwise block direct access to internal network infrastructure.\nIf the target internal service does not require explicit authentication (such as metadata services, internal monitoring endpoints, or unauthenticated development interfaces), the server retrieves the contents of these resources and returns the data back to the attacker-controlled client.\nThis behavior facilitates reconnaissance against the internal network, allows for the interaction with internal REST APIs, and may lead to the exfiltration of credentials or sensitive environment information. The risk is compounded by the fact that the server effectively acts as a proxy, masking the source of the malicious traffic as the trusted server environment.\nThe exploitation does not require special administrative privileges, as the fetch functionality is intended for general use. The lack of proper request filtering remains the critical failure point, allowing for potential secondary exploits against internal services that assume internal origin implies security."
}
CVE-2026-104120: SSRF in mcp-server-fetch Tool (HIGH Severity, CVSS: 7.3) | Sceawere