Server-side Request Forgery in Cyberchitta Scrapling-Fetch-MCP
CVE-2026-81848

5.1MEDIUM

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81848?

A server-side request forgery vulnerability has been identified in the Cyberchitta Scrapling-Fetch-MCP product version 0.2.2 and earlier. This flaw exists within the s_fetch_page and s_fetch_pattern functions located in the src/scrapling_fetch_mcp/_fetcher.py file. By exploiting this vulnerability, a remote attacker could manipulate input, leading to unauthorized requests being sent from the server. It is highly recommended to upgrade to version 0.2.3 where this issue has been addressed. The relevant patch for this vulnerability is identified by commit hash 9f6f34e92c55c3d95566ad9c62aca7327d24533a.

Affected Version(s)

scrapling-fetch-mcp 0.2.0

scrapling-fetch-mcp 0.2.1

scrapling-fetch-mcp 0.2.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mcfly_Zhang (VulDB User)
.