Description
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-26
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the raw_sentry_api component of ddfourtwo sentry-selfhosted-mcp allows an attacker to craft a request that changes the value of the endpoint argument. This manipulation causes the server to perform outbound HTTP requests to arbitrary targets, including internal network resources, thereby enabling disclosure of sensitive data, internal services, or potential lateral movement. The vulnerability can be triggered from outside the system and may lead to confidentiality, integrity, or availability compromise of hosts accessed through the forged requests.

Affected Systems

The affected product is ddfourtwo sentry-selfhosted-mcp, version 0.4.0. No additional versions are identified in the data, so any installation that includes the raw_sentry_api function is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity, and the EPSS score is not provided. The vulnerability is publicly known and exploits have been released, increasing the likelihood of real-world attacks. Although the vulnerability is not yet listed in the CISA KEV catalog, the ability to perform outbound requests remotely makes this issue likely to be attacked by adversaries with network reach to the target. The attack vector is inferred to be remote, based on the description that the exploit can be launched from outside the system.

Generated by OpenCVE AI on August 27, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any vendor‑released updates or patches to sentry‑selfhosted‑mcp that address the raw_sentry_api SSRF flaw.
  • If an update is unavailable, disable or remove the raw_sentry_api component until a fix is released.
  • Implement network‐level controls or input validation to restrict the endpoint parameter to a whitelist of approved destinations.

Generated by OpenCVE AI on August 27, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery
First Time appeared Ddfourtwo
Ddfourtwo sentry-selfhosted-mcp
Weaknesses CWE-918
CPEs cpe:2.3:a:ddfourtwo:sentry-selfhosted-mcp:*:*:*:*:*:*:*:*
Vendors & Products Ddfourtwo
Ddfourtwo sentry-selfhosted-mcp
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ddfourtwo Sentry-selfhosted-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-26T23:45:09.560Z

Reserved: 2026-08-26T19:05:40.944Z

Link: CVE-2026-81421

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T01:18:16.227

Modified: 2026-08-27T01:18:16.227

Link: CVE-2026-81421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T01:30:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)