Impact
A server-side request forgery issue exists in the explore_url function of Model Context Protocol mcp-rdf-explorer 1.0.0. Because the URL parameter is manipulated without proper validation, an attacker can force the server to perform arbitrary HTTP requests. This flaw can lead to data leakage, unauthorized access to internal resources, and potentially the execution of malicious code on the victim machine. The vulnerability is classified as CWE-918.
Affected Systems
The affected product is Model Context Protocol mcp-rdf-explorer version 1.0.0. No other versions or products are currently identified as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the exploit is public and can be triggered remotely. Attackers can exploit the flaw by sending a crafted request to the server’s explore_url endpoint, causing the server to resolve and fetch the specified URL, thus accessing internal or external resources on behalf of the server.
OpenCVE Enrichment