Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

OGX Unauthenticated Server-Side Request Forgery via MCP Tool

OGX (formerly Llama Stack) contains an unauthenticated SSRF vulnerability in the /v1/responses endpoint where MCP tool definitions accept a server_url parameter that is fetched server-side without destination validation, allowing remote attackers to access arbitrary internal addresses including cloud metadata endpoints.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Remote unauthenticated attackers can cause the server to open connections to arbitrary internal addresses and forward attacker-supplied headers and bearer tokens to those destinations, potentially compromising cloud metadata and internal services.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-85666
  2. github.comhttps://github.com/advisories/GHSA-9mg6-c5wp-2g44