Server-Side Request Forgery in jshookmcp by vmoRanV
CVE-2026-49856
4.3MEDIUM
What is CVE-2026-49856?
The jshookmcp server, utilized for JavaScript analysis and security research, contains a server-side request forgery vulnerability in version 0.3.1. The server's authorization policy restricts access to private, loopback, link-local, and reserved targets. However, this can be bypassed using specific MCP client methods to probe internal addresses, thereby exposing sensitive internal network information. This flaw allows unauthorized access to internal network details, which can be exploited if proper security measures are not in place. The issue was resolved in version 0.3.2.
Affected Version(s)
jshookmcp = 0.3.1
