Impact
The get‑html‑skeleton tool in Apify Actors MCP Server only checks that a supplied URL starts with http or https, but it does not verify the host or the resolved address. This flaw allows a caller to direct the tool to any internal or protected endpoint, including private IP ranges and cloud instance metadata services, enabling the server to retrieve sensitive data such as credentials. The downloaded content is then returned in the tool’s response, giving the attacker read access to the targeted service. The vulnerability carries a CVSS score of 8.7, indicating a high‑severity impact on confidentiality and integrity.
Affected Systems
Apify Actors MCP Server versions prior to 0.9.12 are vulnerable. The specific product is Apify Actors MCP Server, and any deployment using a pre‑0.9.12 release is affected.
Risk and Exploitability
A high CVSS score highlights the serious potential for exploitation. The EPSS score is not available, so the current probability of attack is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an internal or any caller to the MCP server; by sending a crafted request containing a malicious URL, an attacker can persuade the server to perform a server‑side request to a protected endpoint and read the response. The flaw does not require elevated privileges on the host, so a local attacker or a network attacker who can reach the MCP server can exploit it.
OpenCVE Enrichment