Vulnerability  ·  2026-10-03

Reference MCP fetch server SSRF: official mcp-server-fetch/mcp-server-everything allow fetching internal/cloud-metadata URLs (CVE-2026-104120)

VulnerabilityMedium impactGlobalCVE-2026-104120
NVD published CVE-2026-104120 on 2026-10-02 (VulDB): the Fetch Tool of the official reference MCP servers mcp-server-fetch and mcp-server-everything up to 2026.6.4 is vulnerable to server-side request forgery via the url/path argument. CVSS 7.3 (v3.1) with exploit maturity marked proof-of-concept — a public exploit is disclosed and the fixing PR has not been merged.
MCP's basic web-fetch server is the single most common tool granted to LLM agents; an SSRF there is an agent-tool attack surface almost every MCP deployment inherits by default. A prompt-injected agent can pivot the server against cloud metadata or internal services, making this a real Agentic/ML-infrastructure risk despite the modest CVSS.
The fetch_url function passes attacker-controlled url/path arguments directly to outbound requests with no SSRF protection, so an LLM agent (or its prompt-injected caller) can make the MCP server fetch private/internal addresses including cloud metadata endpoints.
mcp-server-fetch and mcp-server-everything <= 2026.6.4 (Fetch Tool)
No released fix — the pull request (modelcontextprotocol/servers#4890) awaiting acceptance; monitor the mcp-server-fetch repo for a patched release. Workaround: restrict the server's egress and the set of allowed URLs.
NVD CVE-2026-104120GitHub modelcontextprotocol/servers issue #4492
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →