CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish tool
A server-side request forgery vulnerability was found in Algovate xhs-mcp 0.8.11, where manipulating the media_paths argument of the xhs_publish_content function in the MCP Interface allows remote exploitation. A public exploit exists and the project has not responded to the issue report.
Disclosed 29 April 2026 · Record updated 13 September 2026
Impact
Remote attackers can trigger server-side request forgery via a crafted MCP tool argument; exploit code is publicly available and no vendor fix has been issued.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7417
