Impact
The vulnerability allows an authenticated user to inject an OpenAPI specification that contains external $ref references, internal network addresses. This Server‑Side Request Forg, and other private endpoints that are normally unreachable externally. The impact is the unauthorized disclosure or potential manipulation of confidential internal services.
Affected Systems
Affected products include FrontMCP, @frontmcp/adapters, and mcp-from-openapi from the AgentFront project. For FrontMCP and @frontmcp/adapters, the vulnerability exists in versions 1.2.1 through 1.5.0, with the fix shipped in 1.5.0. For mcp-from-openapi, the issue exists from 2.3.0 through 2.5.0, with the patch delivered in 2.5.0. The CVE references GitHub releases and pull requests for precise version details.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. EPSS is less than 1%, but the issue requires an authenticated and authorized user to configure or import a spec, limiting the open‑world attack surface. Once the vulnerable component is reachable and configuration ability is granted, an attacker can otherwise isolated internal resources. The lack of mitigation in user‑controlled code and the potential reach to sensitive endpoints make timely remediation important.
OpenCVE Enrichment
Github GHSA