PT-2026-82564 · Mcp Use · Mcp-Use

·

CVE-2026-81091

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mcp-use (affected versions not specified)
Description The proxy middleware in the inspector forwards requests to a destination specified by the caller. The mountMcpProxy function in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts reads the target from the X-Target-URL header or the mcp target parameter and proxies the request without inspecting the host. This allows the acceptance of loopback, link-local, and private addresses, as well as names that resolve to them. Additionally, validation is not reapplied to redirects returned by the destination. Consequently, a caller can force the server to issue requests to addresses reachable only from the host where the server is running and read the responses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81091
GHSA-F2JG-RM2X-HC5P

Affected Products

Mcp-Use