APIFold webhook endpoint accepts unauthenticated arbitrary JSON
APIFold's webhook endpoint fails to validate signatures or require authentication, allowing unauthenticated attackers to inject arbitrary payloads into Redis and PostgreSQL. The vulnerability was patched in commit 7f19b52280f414f57af2b79a95333d1c8fbeece5.
Disclosed 23 July 2026 · Record updated 13 September 2026
Impact
Unauthenticated network clients can inject arbitrary payloads that are subsequently served as trusted resource state to legitimate MCP clients
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47769
