Impact
A flaw exists in AIAnytime Awesome‑MCP‑Server that allows an attacker to manipulate the url argument in the mcp‑wiki/wiki‑summary endpoint. By supplying an arbitrary URL, the server performs outbound HTTP requests, creating a server‑side request forgery weakness (CWE‑918). This issue can be triggered remotely and a publicly available exploit has been posted.
Affected Systems
The vulnerability affects any instance of AIAnytime Awesome‑MCP‑Server that contains code up to commit a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Because the project uses a rolling‑release model, specific fixed versions are not published; therefore, all deployments using code at or before that commit remain vulnerable until a newer commit is deployed.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The SSRF capability could allow an attacker to direct the server to fetch internal or otherwise inaccessible resources, potentially exposing sensitive data or enabling further attacks. The attack is remotely triggerable and a published exploit exists, so organizations should treat the risk as moderate to high depending on exposure.
OpenCVE Enrichment