Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF in Tencent CloudBase-MCP open-url endpoint (CVE-2026-7221)

A server-side request forgery vulnerability (CVE-2026-7221) was found in TencentCloudBase CloudBase-MCP up to version 2.17.0, where the openUrl function in the open-url API endpoint fails to validate the req.body.url argument, allowing remote exploitation. A public exploit exists and the issue is fixed in version 2.17.1.

Disclosed 28 April 2026 · Record updated 13 September 2026

Impact

Remote attackers can coerce the MCP server into making arbitrary server-side requests via the open-url API endpoint; exploit code is publicly available.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7221