PT-2026-82564 · Mcp Use · Mcp-Use
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mcp-use (affected versions not specified)
Description
The proxy middleware in the inspector forwards requests to a destination specified by the caller. The
mountMcpProxy function in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts reads the target from the X-Target-URL header or the mcp target parameter and proxies the request without inspecting the host. This allows the acceptance of loopback, link-local, and private addresses, as well as names that resolve to them. Additionally, validation is not reapplied to redirects returned by the destination. Consequently, a caller can force the server to issue requests to addresses reachable only from the host where the server is running and read the responses.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Use