Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery | |
| First Time appeared |
Modelcontextprotocol
Modelcontextprotocol mcp-server-everything Modelcontextprotocol mcp-server-fetch |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:* cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Modelcontextprotocol
Modelcontextprotocol mcp-server-everything Modelcontextprotocol mcp-server-fetch |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-02T02:15:18.514Z
Reserved: 2026-10-01T18:15:10.419Z
Link: CVE-2026-104120
No data.
Status : Received
Published: 2026-10-02T03:16:38.840
Modified: 2026-10-02T03:16:38.840
Link: CVE-2026-104120
No data.
OpenCVE Enrichment
Updated: 2026-10-02T03:30:17Z