SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146)
A publicly disclosed server-side request forgery vulnerability in the axios-based HTTP request handler of the web-scraper server in the open-source mcp-data-vis MCP project allows remote attackers to make the server issue arbitrary requests. The maintainer was notified via a GitHub issue but has not responded, and the rolling-release project has no fixed version.
Disclosed 27 April 2026 · Record updated 13 September 2026
Impact
Remote attackers can trigger server-side request forgery through the MCP web-scraper tool; exploit details are public and no fix is available.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7146
