PT-2026-70356 · Unknown · Activepieces
CVE-2026-73082
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Activepieces versions prior to 0.82.0
Description
An authenticated user can exploit a Server-Side Request Forgery (SSRF) issue, where the server makes outbound HTTP or SSE (Server-Sent Events) requests to a user-supplied
serverUrl without proper validation. This allows the attacker to force the server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts to probe network reachability from the host. The issue occurs at the '/api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool' endpoint.Recommendations
Update to version 0.82.0.
Avoid using the
serverUrl parameter in the '/api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool' endpoint until the update is applied.Exploit
Fix
SSRF
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activepieces