Server-Side Request Forgery Vulnerability in ModelContextProtocol's Fetch Tool
CVE-2026-104120
Key Information:
- Vendor
Modelcontextprotocol
- Vendor
- CVE Published:
- 2 October 2026
Badges
What is CVE-2026-104120?
A security flaw has been identified in ModelContextProtocol's Fetch Tool, affecting versions up to 2026.6.4. The vulnerability resides in the fetch_url function within the server.py file of the mcp-server-fetch and mcp-server-everything components. Attackers can manipulate the url/path argument, potentially allowing them to perform server-side request forgery (SSRF) attacks. This vulnerability can be exploited remotely, posing a significant risk to affected systems. A public disclosure of the exploit has occurred, and a pull request for a fix is currently pending acceptance.
Affected Version(s)
mcp-server-everything 2026.6.0
mcp-server-everything 2026.6.1
mcp-server-everything 2026.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
