Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146)

A publicly disclosed server-side request forgery vulnerability in the axios-based HTTP request handler of the web-scraper server in the open-source mcp-data-vis MCP project allows remote attackers to make the server issue arbitrary requests. The maintainer was notified via a GitHub issue but has not responded, and the rolling-release project has no fixed version.

Disclosed 27 April 2026 · Record updated 13 September 2026

Impact

Remote attackers can trigger server-side request forgery through the MCP web-scraper tool; exploit details are public and no fix is available.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7146