Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Apify MCP Server API Token Exposure via URL Redirection

The Apify MCP server prior to version 0.10.11 allows malicious Actor publishers to redirect connections to third-party hosts and steal API tokens through improper URL validation in the getActorMCPServerURL function. Victims must invoke or inspect the attacker-controlled Actor to be affected.

Disclosed 18 August 2026 · Record updated 13 September 2026

Impact

API tokens and access to Actors, stored data, and billable compute resources could be exposed to attackers through malicious Actor definitions.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-50143