Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handling

A GitHub advisory reports that the patch for an earlier SSRF issue (CVE-2026-39885) in mcp-from-openapi 2.3.0 can be bypassed, letting untrusted OpenAPI specs loaded by FrontMCP 1.2.1 trigger backend-origin requests to loopback or private services via DNS-to-loopback names, redirects, and IPv4-mapped IPv6 forms. In hosted or multi-user FrontMCP deployments where users can import specs, this can expose internal APIs not reachable externally.

Disclosed 11 September 2026 · Record updated 13 September 2026

Impact

Server-side request forgery from FrontMCP backends during OpenAPI tool generation, potentially exposing internal admin APIs, metadata-like services and other internal network endpoints; demonstrated with a local proof-of-concept canary.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-65h7-9wrw-629c