Unknown · Fetcher-Mcp · CVE-2026-74858
**Name of the Vulnerable Software and Affected Versions**
jae-jae fetcher-mcp versions prior to 0.4.0
**Description**
An issue exists in the URL Validation component where the `fetch url()` and `fetch urls()` functions in the `/latest/meta-data/iam/security-credentials/` file are susceptible to manipulation. This allows a remote attacker to perform server-side request forgery (SSRF), a technique where the attacker induces the server to make requests to an unintended location.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the `fetch url()` and `fetch urls()` functions.