Description
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_methods() in meta_ads_mcp/core/utils.py, where httpx.AsyncClient uses follow_redirects=True and performs HTTP requests without validating the scheme, host, or resolved IP address. In a streamable-http deployment, a network caller can use any non-empty authorization value because Meta credential validation occurs after the image download, then direct the server to loopback services, private-network addresses, cloud metadata endpoints, or redirect-chained internal targets. The resulting server-side request forgery can expose internal data, invoke state-changing internal services, or disrupt reachable services. This issue is fixed in version 1.0.115.
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Meta Ads MCP is a Model Context Protocol server that allows AI assistants to run Meta Ads. Until release 1.0.115, the upload_ad_image tool accepted an attacker‑controlled image_url supplied by a network caller. The URL was forwarded to try_multiple_download_methods(), which used httpx.AsyncClient with follow_redirects=True and performed HTTP requests without validating the scheme, host, or resolved IP address. Because Meta credential validation occurs after the image download, the server can be directed to loopback services, private‑network addresses, cloud metadata endpoints, or internally chained redirects. This SSRF can expose internal data, trigger state‑changing calls to internal services, or disrupt services. The vulnerability is remedied in version 1.0.115.

Affected Systems

The vulnerability affects pipeboard‑co:meta‑ads‑mcp deployments running any version earlier than 1.0.115. All installations of this MCP server, regardless of hosting environment or configuration, are vulnerable to the SSRF described in this CVE.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. The EPSS score of less than 1% suggests that public exploitation is unlikely at present, and the vulnerability is not yet listed in CISA’s KEV catalog. The SSRF can be exercised remotely by sending a crafted request to the upload_ad_image endpoint; the attacker merely needs to supply a non‑empty Authorization header, which is validated after the image download, making the attack trivial in contacting internal targets such as cloud‑metadata endpoints or other sensitive services, a successful exploitation could compromise confidentiality, integrity or availability of the internal system.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Meta Ads MCP to version 1.0.115 or later, which includes validation of image URLs and prevents internal requests.
  • If an upgrade is delayed, restrict or disable the upload_ad_image endpoint for unauthenticated or untrusted users and enforce strict role‑based access control.
  • Configure firewall or network controls to block outgoing connections from the MCP server to private‑network ranges (10.0.0.0/8, 172.16.0.0/16), localhost (127.0.0.1), and known cloud metadata hosts, thereby mitigating the impact of any remaining SSRF.
  • Implement server‑side URL filtering to allow only external HTTP or HTTPS addresses, reject other schemes, and limit or disable redirect following for the image download process.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-45gf-fjxp-cjpq meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Pipeboard-co
Pipeboard-co meta-ads-mcp
Vendors & Products Pipeboard-co
Pipeboard-co meta-ads-mcp

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_methods() in meta_ads_mcp/core/utils.py, where httpx.AsyncClient uses follow_redirects=True and performs HTTP requests without validating the scheme, host, or resolved IP address. In a streamable-http deployment, a network caller can use any non-empty authorization value because Meta credential validation occurs after the image download, then direct the server to loopback services, private-network addresses, cloud metadata endpoints, or redirect-chained internal targets. The resulting server-side request forgery can expose internal data, invoke state-changing internal services, or disrupt reachable services. This issue is fixed in version 1.0.115.
Title Meta Ads MCP: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Pipeboard-co Meta-ads-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T14:44:41.503Z

Reserved: 2026-06-15T19:04:14.456Z

Link: CVE-2026-54549

cve-icon Vulnrichment

Updated: 2026-09-16T14:44:18.236Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:23.073

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)