Impact
A flaw in the s_fetch_page/s_fetch_pattern function of scrapling‑fetch‑mcp enables server‑side request forgery (CWE‑918). When an attacker supplies a crafted value to this function, the service will initiate an outbound HTTP request to an arbitrary target, which can expose internal hosts, bypass network controls, or facilitate further attacks. The impact includes potential data disclosure or manipulation of downstream systems. The vulnerability is documented as existing in all releases up to 0.2.2 and is addressed in 0.2.3.
Affected Systems
The affected product is cyberchitta scrapling‑fetch‑mcp, versions up to and including 0.2.2. Upgrading to 0.2.3 removes the flaw. No other versions or variants are reported to be affected.
Risk and Exploitability
The CVSS score of 5.1 categorises the issue as moderate severity, and no EPSS value is provided, indicating no publicly available exploitation data at the time of this analysis. The vulnerability can be triggered remotely by supplying a malicious parameter to the affected function. Because the vector relies on remote input and the code has not been mitigated by additional controls, the likelihood of exploitation is non‑zero but not highly probable. The issue is not listed in the CISA KEV catalogue, suggesting no widespread use yet.
OpenCVE Enrichment