SSRF and GraphQL Expression Injection Vulnerability in Apache SkyWalking MCP
CVE-2026-34884
Currently unrated
What is CVE-2026-34884?
The vulnerability in Apache SkyWalking MCP allows for server-side request forgery (SSRF) through the set_skywalking_url tool, coupled with a GraphQL expression injection weakness. This flaw can potentially be exploited to perform unauthorized actions within the application and access internal resources. Users are strongly advised to upgrade to version 0.2.0 or later to mitigate this risk and ensure secure operation.
Affected Version(s)
Apache SkyWalking MCP 0.1.0