Description
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution to OpenAPIToolGenerator.fromURL() and OpenAPIToolGenerator.fromJSON(). The external $ref guard checks parsed hostname strings without resolving addresses, pinning validated addresses, revalidating redirect targets, or normalizing IPv4-mapped IPv6. An authenticated user who can import or configure an OpenAPI specification in a hosted or multi-user deployment can use DNS-to-loopback resolution, redirect-to-loopback behavior, or IPv4-mapped IPv6 loopback forms to cause backend-origin requests to internal services. This can expose internal administrative APIs, metadata-like services, and other private network endpoints. The practical impact is lower when only a trusted local administrator can configure OpenAPI specs, and disabling external reference protocols prevents the external $ref request. This issue is fixed in mcp-from-openapi 2.5.0 and frontmcp and @frontmcp/adapters 1.5.0.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Internal Network Disclosure via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to inject an OpenAPI specification that contains external $ref references, internal network addresses. This Server‑Side Request Forg, and other private endpoints that are normally unreachable externally. The impact is the unauthorized disclosure or potential manipulation of confidential internal services.

Affected Systems

Affected products include FrontMCP, @frontmcp/adapters, and mcp-from-openapi from the AgentFront project. For FrontMCP and @frontmcp/adapters, the vulnerability exists in versions 1.2.1 through 1.5.0, with the fix shipped in 1.5.0. For mcp-from-openapi, the issue exists from 2.3.0 through 2.5.0, with the patch delivered in 2.5.0. The CVE references GitHub releases and pull requests for precise version details.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. EPSS is less than 1%, but the issue requires an authenticated and authorized user to configure or import a spec, limiting the open‑world attack surface. Once the vulnerable component is reachable and configuration ability is granted, an attacker can otherwise isolated internal resources. The lack of mitigation in user‑controlled code and the potential reach to sensitive endpoints make timely remediation important.

Generated by OpenCVE AI on September 20, 2026 at 16:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mcp‑from‑openapi to version 2.5.0 or later
  • Upgrade frontmcp and @frontmcp/adapters to version 1.5.0 or later
  • If immediate upgrade is not possible, disable external $ref protocol support or restrict OpenAPI specification import to trusted administrators only

Generated by OpenCVE AI on September 20, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-65h7-9wrw-629c FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution to OpenAPIToolGenerator.fromURL() and OpenAPIToolGenerator.fromJSON(). The external $ref guard checks parsed hostname strings without resolving addresses, pinning validated addresses, revalidating redirect targets, or normalizing IPv4-mapped IPv6. An authenticated user who can import or configure an OpenAPI specification in a hosted or multi-user deployment can use DNS-to-loopback resolution, redirect-to-loopback behavior, or IPv4-mapped IPv6 loopback forms to cause backend-origin requests to internal services. This can expose internal administrative APIs, metadata-like services, and other private network endpoints. The practical impact is lower when only a trusted local administrator can configure OpenAPI specs, and disabling external reference protocols prevents the external $ref request. This issue is fixed in mcp-from-openapi 2.5.0 and frontmcp and @frontmcp/adapters 1.5.0.
Title mcp-from-openapi: Bypass of OpenAPI external $ref SSRF fix in latest FrontMCP and mcp-from-openapi
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:06:53.148Z

Reserved: 2026-07-07T19:41:00.004Z

Link: CVE-2026-59973

cve-icon Vulnrichment

Updated: 2026-09-16T16:06:33.577Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:18.327

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-59973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)