@jshookmcp/jshook SSRF bypass via ICMP and traceroute tools
CVE-2026-49856 in @jshookmcp/jshook version 0.3.1 allows MCP clients to bypass SSRF authorization policies by using ICMP probe and traceroute tools to probe internal network addresses. The vulnerability exposes internal reachability and route mapping from the server's network position.
Occurred 13 August 2026 · Disclosed 13 August 2026 · Record updated 13 September 2026
Impact
MCP clients with access to an active network domain can probe internal addresses and map internal network routes, bypassing SSRF protections.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49856
