Impact
A flaw was identified in the fetcher‑mcp component (up to 0.3.9) within the function fetch_url/fetch_urls that validates URLs received from the path /latest/meta-data/iam/security‑credentials/. An attacker can manipulate the URL passed to this function, causing the component to make outgoing requests to arbitrary destinations. This permits attacker controlled network traffic from the host, potentially accessing internal metadata services and other protected resources.
Affected Systems
The vulnerability affects the jae‑jae fetcher‑mcp product, versions up to and including 0.3.9.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. While the EPSS score is not available, the described remote exploitation path without any local privilege prerequisites means the risk to any exposed instance is significant. The vulnerability is not listed in CISA KEV but can be triggered remotely by supplying a crafted URL to the fetcher‑mcp service. Once exploited, the attacker may gain privileged access to internal services via SSRF.
OpenCVE Enrichment