Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Rowboat fails to validate custom MCP server and webhook URLs

Rowboat through version 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations and perform server-side request forgery attacks against internal services and cloud metadata endpoints.

Disclosed 5 September 2026 · Record updated 13 September 2026

Impact

Authenticated users can perform server-side request forgery and enumerate internal network topology by configuring arbitrary MCP server and webhook URLs.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-86122
  2. github.comhttps://github.com/advisories/GHSA-jmxm-qmrf-xrpp