Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF in AIAnytime Awesome-MCP-Server wiki-summary tool (CVE-2026-14748)

A server-side request forgery flaw in the mcp-wiki/wiki-summary component of AIAnytime's Awesome-MCP-Server allows remote attackers to manipulate the 'url' argument in mcp-wiki/src/mcp_wiki/server.py. An exploit has been published and the project has not responded to the issue report.

Disclosed 5 July 2026 · Record updated 13 September 2026

Impact

Remote attackers can trigger server-side requests from the MCP server via the unvalidated url argument; a public exploit is available and no fix has been issued as the project uses a rolling release model.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-14748