Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-7729: SSRF in pixelsock directus-mcp 1.0.0 MCP interface

A server-side request forgery flaw was disclosed in the validateUrl function of index.ts in pixelsock's directus-mcp 1.0.0 MCP server, where manipulating the fileUrl argument allows remote attackers to make the server issue arbitrary requests. A public exploit has been released and the fix pull request is still awaiting acceptance.

Disclosed 4 May 2026 · Record updated 13 September 2026

Impact

Remotely exploitable server-side request forgery via the MCP interface's fileUrl argument; exploit code is public and no accepted fix is available yet.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7729