Vulnerability  ·  2026-10-03

Official MCP reference servers mcp-server-fetch / mcp-server-everything: SSRF via fetch_url with public exploit (CVSS 7.3)

VulnerabilityMedium impactGlobalCVE-2026-104120
VulDB/NVD published an SSRF (CWE-918) in the official mcp-server-fetch and mcp-server-everything reference servers affecting versions up to 2026.6.4. The exploit has been publicly disclosed and the fixing pull request was still awaiting merge at publication (2026-10-02).
This is the official Anthropic-maintained MCP fetch reference implementation — the de-facto 'browse the web' tool that agents wire up by default. It is unauthenticated at the tool-call level and reachable by any LLM agent granted the tool, so a prompt-injected agent can pivot it into SSRF against internal/cloud-metadata infrastructure.
A crafted url/path argument to the Fetch Tool's fetch_url causes server-side request forgery; an agent steered via prompt injection (or a direct caller) can make the MCP server reach internal services, including cloud metadata endpoints.
modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4 (Fetch Tool, fetch_url function)
Watch the pending fix PR (https://github.com/modelcontextprotocol/servers/pull/4890); restrict the fetch server's egress, run it with least-privilege network access, and treat attacker-supplied URLs as untrusted.
NVD CVE-2026-104120GitHub issue modelcontextprotocol/servers#4492Fix PR modelcontextprotocol/servers#4890
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →