Server-Side Request Forgery Vulnerability in Meta Ads MCP by Meta
CVE-2026-54549
8.3HIGH
What is CVE-2026-54549?
The vulnerability in Meta Ads MCP allows unauthorized access through a server-side request forgery (SSRF) attack due to improper validation of user-controlled input in image URLs. This flaw enables attackers to exploit Meta Ads' upload_ad_image functionality to perform HTTP requests without adequate safeguards. By leveraging an unvalidated URL scheme, intruders can potentially access internal resources, disrupt services, or extract confidential data from internal networks. The issue was resolved with the release of version 1.0.115, where enhanced validation procedures were implemented to mitigate the risk.
Affected Version(s)
meta-ads-mcp < 1.0.115
