CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton tool
The get-html-skeleton tool in Apify MCP Server validated URLs only for syntax, allowing callers to request internal endpoints including cloud metadata services. Version 0.9.12 removes the vulnerable tool.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Attackers could access cloud instance metadata and credentials through server-side request forgery via the get-html-skeleton tool
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81093
