PT-2026-70356 · Unknown · Activepieces

CVE-2026-73082

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Activepieces versions prior to 0.82.0
Description An authenticated user can exploit a Server-Side Request Forgery (SSRF) issue, where the server makes outbound HTTP or SSE (Server-Sent Events) requests to a user-supplied serverUrl without proper validation. This allows the attacker to force the server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts to probe network reachability from the host. The issue occurs at the '/api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool' endpoint.
Recommendations Update to version 0.82.0. Avoid using the serverUrl parameter in the '/api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool' endpoint until the update is applied.

Exploit

Fix

SSRF

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73082
GHSA-7QX9-Q4XX-RH59

Affected Products

Activepieces