Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton tool

The get-html-skeleton tool in Apify MCP Server validated URLs only for syntax, allowing callers to request internal endpoints including cloud metadata services. Version 0.9.12 removes the vulnerable tool.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Attackers could access cloud instance metadata and credentials through server-side request forgery via the get-html-skeleton tool

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81093