Impact
Meta Ads MCP is a Model Context Protocol server that allows AI assistants to run Meta Ads. Until release 1.0.115, the upload_ad_image tool accepted an attacker‑controlled image_url supplied by a network caller. The URL was forwarded to try_multiple_download_methods(), which used httpx.AsyncClient with follow_redirects=True and performed HTTP requests without validating the scheme, host, or resolved IP address. Because Meta credential validation occurs after the image download, the server can be directed to loopback services, private‑network addresses, cloud metadata endpoints, or internally chained redirects. This SSRF can expose internal data, trigger state‑changing calls to internal services, or disrupt services. The vulnerability is remedied in version 1.0.115.
Affected Systems
The vulnerability affects pipeboard‑co:meta‑ads‑mcp deployments running any version earlier than 1.0.115. All installations of this MCP server, regardless of hosting environment or configuration, are vulnerable to the SSRF described in this CVE.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score of less than 1% suggests that public exploitation is unlikely at present, and the vulnerability is not yet listed in CISA’s KEV catalog. The SSRF can be exercised remotely by sending a crafted request to the upload_ad_image endpoint; the attacker merely needs to supply a non‑empty Authorization header, which is validated after the image download, making the attack trivial in contacting internal targets such as cloud‑metadata endpoints or other sensitive services, a successful exploitation could compromise confidentiality, integrity or availability of the internal system.
OpenCVE Enrichment
Github GHSA