Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Apify MCP Server URL Validation Bypass

The Apify MCP server's fetch-apify-docs tool failed to properly validate documentation URLs, allowing attackers to bypass domain allowlisting and return arbitrary content to AI agents. The vulnerability was fixed in version 0.9.21.

Disclosed 16 July 2026 · Record updated 13 September 2026

Impact

Attackers could bypass URL validation to return arbitrary fetched content to LLMs using crafted URLs like https://docs.apify.com.evil.com/

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-46341