Impact
The vulnerability arises from improper validation of the URL or path argument in the fetch_url function of the Fetch Tool server.py. This flaw allows an attacker to cause the server to make arbitrary HTTP requests, leading to server‑side request forgery. The weakness is classified as CWE‑918 and enables remote attackers to exploit the server without authentication, potentially exposing internal services or leaking private data.
Affected Systems
The affected products are modelcontextprotocol mcp‑server‑everything and modelcontextprotocol mcp‑server‑fetch. All releases up to and including version 2026.6.4 are vulnerable. The components reside in the Fetch Tool module and are used to retrieve data from external URLs, making them a primary target for exploitation.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the exploit is available publicly with no mitigation from the vendor yet. Because the EPSS score is not available, the exploitation probability is uncertain, but the presence of a public disclosure and an open pull request suggests that attackers could readily deploy the SSRF attack. The vulnerability is not listed in the CISA KEV catalog as of the data provided, but the potential for internal network reconnaissance or data exfiltration remains high.
OpenCVE Enrichment