No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcp-use
Mcp-use mcp-use |
|
| Vendors & Products |
Mcp-use
Mcp-use mcp-use |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it without inspecting the host, so loopback, link-local and private addresses were all accepted, as were names that resolve to them, and the validation was not reapplied to a redirect the destination returned. A caller could therefore make the server issue requests to addresses reachable only from the host it runs on and read the responses. The current code calls isSafeProxyTarget, which checks the resolved address against private, loopback and link-local ranges before proxying and bounds the number of redirects followed. | |
| Title | mcp-use Inspector Proxy Server-Side Request Forgery via Caller-Supplied Target URL | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T18:12:23.691Z
Reserved: 2026-08-26T16:00:30.592Z
Link: CVE-2026-81091
Updated: 2026-08-27T18:12:20.653Z
Status : Received
Published: 2026-08-27T17:20:51.183
Modified: 2026-08-27T20:18:49.180
Link: CVE-2026-81091
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:14:38Z