Impact
Rowboat up to version 0.9.1 allows authenticated users to configure custom MCP server and webhook URLs without validating them, creating a server‑side request forgery (SSRF) vector. By supplying arbitrary URLs, an attacker can direct the application to send requests to any internal address, including cloud metadata services, and gather network topology or other sensitive data. The vulnerability is a moderate‑severity flaw (CVSS 5.3) that does not provide direct remote code execution but permits significant information disclosure and potential lateral movement within the internal network.
Affected Systems
The affected product is Rowboat from Rowboat Labs, specifically all releases up to 0.9.1. The vulnerability exists in the code paths that handle custom MCP server and webhook URL configuration in the agent‑tools module and the add‑custom‑mcp‑server use case.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, making it unclear how frequently this exploit is observed. Because the vulnerability requires authenticated access, an attacker only needs valid credentials to misconfigure URLs. The attacker can then use the server’s outbound connections to enumerate internal services or access private cloud metadata endpoints. The flaw is not listed in CISA’s KEV catalog, so current public exploitation evidence is limited, but the potential for internal data leakage remains high.
OpenCVE Enrichment