Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF in horizon921 mcpilot 0.1.0 MCP API call endpoint (CVE-2026-10280)

A server-side request forgery flaw in the MCP API call endpoint (client/src/app/api/mcp/call/route.ts) of horizon921 mcpilot 0.1.0 allows remote attackers to manipulate the serverBaseUrl argument. A public exploit has been released and the project has not responded to the issue report.

Disclosed 1 June 2026 · Record updated 13 September 2026

Impact

Remote attackers can coerce the MCP call endpoint into making arbitrary server-side requests; exploit code is publicly available and no vendor fix has been issued.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-10280