Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF in dmitryglhf mcp-url-downloader MCP server (CVE-2026-7158)

A server-side request forgery vulnerability was disclosed in the _validate_url_safe function of the dmitryglhf mcp-url-downloader MCP server, allowing remote attackers to manipulate the url argument and force the server to make unintended requests. The exploit is public and the project has not responded to the issue report.

Disclosed 27 April 2026 · Record updated 13 September 2026

Impact

Remote attackers can bypass URL safety validation to trigger server-side request forgery via the MCP server's download tool; exploit code is publicly disclosed and no fix is available as the project uses a rolling release and has not responded.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7158