Description
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.





This issue affects Apache SkyWalking MCP: 0.1.0.

Users are recommended to upgrade to version 0.2.0, which fixes this issue.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to exploit a Server Side Request Forgery via the set_skywalking_url tool and inject arbitrary expressions into GraphQL queries that are processed by the SkyWalking MCP server. The SSRF capability can enable requests to arbitrary internal or external resources, while the GraphQL injection allows manipulation of query expressions that could lead to unauthorized data exposure or further compromise.

Affected Systems

Apache SkyWalking MCP is affected in the 0.1.0 release. Users are recommended to upgrade to version 0.2.0 which resolves the issue.

Risk and Exploitability

The EPSS score is <1% and the vulnerability is not listed in CISA KEV. The CVSS score of 9.8 indicates a critical risk level, reflecting the severe impact of SSRF and GraphQL expression injection. Attackers would likely interact with the web interface or REST endpoints that expose the set_skywalking_url tool and GraphQL API; such exploitation could be achieved without authentication if those endpoints are publicly accessible. The exact attack vector is inferred from the description and not explicitly detailed in the advisory.

Generated by OpenCVE AI on August 21, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache SkyWalking MCP to version 0.2.0 or later
  • If upgrading is not immediately possible, restrict or disable access to the set_skywalking_url tool and limit the sources of incoming requests
  • Apply network segmentation or firewall rules to block outbound SRRF traffic from the SkyWalking MCP server to private or external resources

Generated by OpenCVE AI on August 21, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:skywalking_mcp:*:*:*:*:*:*:*:*

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 18 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
References

Tue, 18 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache skywalking Mcp
Vendors & Products Apache
Apache skywalking Mcp

Tue, 18 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.
Title Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server
Weaknesses CWE-918
References

Subscriptions

Apache Skywalking Mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-19T13:28:04.910Z

Reserved: 2026-03-31T07:33:52.367Z

Link: CVE-2026-34884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T08:16:42.470

Modified: 2026-09-02T14:05:31.893

Link: CVE-2026-34884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)