Impact
The vulnerability lies in the upload_media function of aerostackdev’s Aerostack‑MCP, where an attacker can supply a malicious media_url parameter. This causes the server to fetch the indicated resource, exposing the application to Server‑Side Request Forgery (CWE‑918). The flaw enables a remote attacker to trigger outbound connections from the host to arbitrary URLs, potentially retrieving sensitive internal data or facilitating lateral movement within the network.
Affected Systems
The affected product is aerostackdev Aerostack‑MCP, specifically the mcp‑whatsapp module’s upload_media handler. Because Aerostack‑MCP follows a rolling‑release model, the product has no discrete version numbers; any deployment that has not incorporated a commit more recent than f88d91347115e09ba23 remains susceptible.
Risk and Exploitability
The CVSS score of 5.3 and an EPSS score of less than 1 % indicate a moderate severity but a very low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog, so no widely known exploits have been observed. Nonetheless, the problem can be leveraged by any actor who can reach the public upload_media endpoint, enabling the server to connect to internal or external addresses of the attacker’s choosing.
OpenCVE Enrichment