Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339)

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3 and 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server. An attacker with access to the MCP server in stdio mode can supply internal URLs as file attachments in post creation requests to perform server-side request forgery and exfiltrate data from internal network services.

Disclosed 26 June 2026 · Record updated 13 September 2026

Impact

Server-side request forgery enabling exfiltration of data from internal network services reachable by the MCP server.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-4339