Ddfourtwo · Sentry-Selfhosted-Mcp · CVE-2026-81421
**Name of the Vulnerable Software and Affected Versions**
ddfourtwo sentry-selfhosted-mcp version 0.4.0
**Description**
A flaw in the `raw sentry api` component allows for server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. This is achieved by manipulating the `endpoint` argument within an unknown function, enabling remote attacks.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `raw sentry api` component or avoid using the `endpoint` argument until a patch is released.