Impact
The vulnerability resides in the ReadResourceRequestSchema function within initResources.ts. Manipulation of the request.params.uri argument allows an attacker to cause the server to send HTTP requests to arbitrary internal or external resources. As a result, an attacker could exfiltrate sensitive data, bypass authentication, or potentially exploit downstream services. The weakness corresponds to CWE‑918.
Affected Systems
The affected component is Alibaba Cloud DataWorks MCP Server up to version 1.0.43. Any deployment of this product using the stated version range is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be launched remotely, meaning a threat actor only needs network access to the exposed API endpoint. Given the lack of an official patch at present, the risk persists until a fix or mitigation is applied.
OpenCVE Enrichment