Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish tool

A server-side request forgery vulnerability was found in Algovate xhs-mcp 0.8.11, where manipulating the media_paths argument of the xhs_publish_content function in the MCP Interface allows remote exploitation. A public exploit exists and the project has not responded to the issue report.

Disclosed 29 April 2026 · Record updated 13 September 2026

Impact

Remote attackers can trigger server-side request forgery via a crafted MCP tool argument; exploit code is publicly available and no vendor fix has been issued.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7417