Server-Side Request Forgery Vulnerability in Meta Ads MCP by Meta
CVE-2026-54549

8.3HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-54549?

The vulnerability in Meta Ads MCP allows unauthorized access through a server-side request forgery (SSRF) attack due to improper validation of user-controlled input in image URLs. This flaw enables attackers to exploit Meta Ads' upload_ad_image functionality to perform HTTP requests without adequate safeguards. By leveraging an unvalidated URL scheme, intruders can potentially access internal resources, disrupt services, or extract confidential data from internal networks. The issue was resolved with the release of version 1.0.115, where enhanced validation procedures were implemented to mitigate the risk.

Affected Version(s)

meta-ads-mcp < 1.0.115

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.