Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

mcp-use Inspector Proxy SSRF via Unvalidated Target URL

The proxy middleware in mcp-use's inspector failed to validate the host of requests, allowing callers to make the server issue requests to private, loopback, and link-local addresses and read responses. This server-side request forgery vulnerability has been patched with proper host validation and redirect limiting.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Attackers could make the server issue requests to addresses reachable only from the host it runs on and read the responses, enabling reconnaissance of internal network infrastructure.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81091