Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

@jshookmcp/jshook SSRF bypass via ICMP and traceroute tools

CVE-2026-49856 in @jshookmcp/jshook version 0.3.1 allows MCP clients to bypass SSRF authorization policies by using ICMP probe and traceroute tools to probe internal network addresses. The vulnerability exposes internal reachability and route mapping from the server's network position.

Occurred 13 August 2026 · Disclosed 13 August 2026 · Record updated 13 September 2026

Impact

MCP clients with access to an active network domain can probe internal addresses and map internal network routes, bypassing SSRF protections.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49856