What happened
NVD published CVE-2026-104120 on 2026-10-02 (VulDB): the Fetch Tool of the official reference MCP servers mcp-server-fetch and mcp-server-everything up to 2026.6.4 is vulnerable to server-side request forgery via the url/path argument. CVSS 7.3 (v3.1) with exploit maturity marked proof-of-concept — a public exploit is disclosed and the fixing PR has not been merged.
Why it matters
MCP's basic web-fetch server is the single most common tool granted to LLM agents; an SSRF there is an agent-tool attack surface almost every MCP deployment inherits by default. A prompt-injected agent can pivot the server against cloud metadata or internal services, making this a real Agentic/ML-infrastructure risk despite the modest CVSS.
Attack vector
The fetch_url function passes attacker-controlled url/path arguments directly to outbound requests with no SSRF protection, so an LLM agent (or its prompt-injected caller) can make the MCP server fetch private/internal addresses including cloud metadata endpoints.
Affected systems
mcp-server-fetch and mcp-server-everything <= 2026.6.4 (Fetch Tool)
Mitigation
No released fix — the pull request (modelcontextprotocol/servers#4890) awaiting acceptance; monitor the mcp-server-fetch repo for a patched release. Workaround: restrict the server's egress and the set of allowed URLs.