惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
T
ThreatConnect
SecWiki News
SecWiki News
F
Future of Privacy Forum
AWS News Blog
AWS News Blog
C
Cisco Blogs
A
Arctic Wolf
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
V2EX
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
M
Microsoft Research Blog - Microsoft Research
Google Online Security Blog
Google Online Security Blog
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
F
Fox-IT International blog
S
Security @ Cisco Blogs
博客园 - 司徒正美
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Comments on: Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
GbyAI
GbyAI
Project Zero
Project Zero
腾讯CDC
T
Tailwind CSS Blog

Full Disclosure

Full Disclosure: [SECURITY ADVISORY] CVE-2021-21735 Full Disclosure: [SECURITY ADVISORY] CVE-2026-34474 Full Disclosure: [SECURITY ADVISORY] CVE-2026-34472 Full Disclosure: [SECURITY ADVISORY] CVE-2026-34473 Multiple vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect Full Disclosure: APPLE-SA-05-13-2026-1 Safari 26.5 Full Disclosure: APPLE-SA-05-11-2026-11 visionOS 26.5 Full Disclosure: APPLE-SA-05-11-2026-10 watchOS 26.5 Full Disclosure: APPLE-SA-05-11-2026-9 tvOS 26.5 Full Disclosure: APPLE-SA-05-11-2026-8 macOS Sonoma 14.8.7 Full Disclosure: APPLE-SA-05-11-2026-7 macOS Sequoia 15.7.7 Full Disclosure: APPLE-SA-05-11-2026-6 macOS Tahoe 26.5 APPLE-SA-05-11-2026-5 iOS 15.8.8 and iPadOS 15.8.8 APPLE-SA-05-11-2026-4 iOS 16.7.16 and iPadOS 16.7.16 Full Disclosure: APPLE-SA-05-11-2026-3 iPadOS 17.7.11 APPLE-SA-05-11-2026-2 iOS 18.7.9 and iPadOS 18.7.9 APPLE-SA-05-11-2026-1 iOS 26.5 and iPadOS 26.5 Impersonation attacks on Edupage portal Edupage web and mobile application authorization bypass leaks PII and IBAN codes Full Disclosure: Dovecot Security Advisory OXDC-2026-0002 Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_pro (CVE-2024-13971) Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP (CVE-2024-39847) ESP-RFID-Tool v2 PRO — Full Public Disclosure Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App DLL Hijacking in EfficientLab Controlio (cloud-based employee monitoring service) Broken Access Control in Config Endpoint in LiteLLM Exposed Private Key of X.509 Certificate in SAP HANA Cockpit & SAP HANA Database Explorer APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8 APPLE-SA-04-22-2026-1 iOS 26.4.2 and iPadOS 26.4.2 When Trusted Tools Become Attack Primitives [KIS-2026-08] SocialEngine <= 7.8.0 (get-memberall) SQL Injection Vulnerability [KIS-2026-07] SocialEngine <= 7.8.0 Blind Server-Side Request Forgery Vulnerability Full Disclosure: Trojan-Spy.Win32.Small / Remote Command Execution Full Disclosure: [IWCC 2026] CfP: 15th International Workshop on Cyber Crime GoAnywhere MFT Email HTML Injection Full Disclosure: CyberDanube Security Research 20260408-1 Full Disclosure: CyberDanube Security Research 20260408-0 Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS Broken Access Control in Open WebUI Full Disclosure: SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) 14 Third-Party Endpoints, 6 Countries, Zero User Visibility [KIS-2026-06] MetInfo CMS <= 8.1 (weixinreply.class.php) PHP Code Injection Vulnerability [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability Full Disclosure: APPLE-SA-03-24-2026-10 Xcode 26.4 Full Disclosure: APPLE-SA-03-24-2026-9 Safari 26.4 Full Disclosure: APPLE-SA-03-24-2026-8 visionOS 26.4 Full Disclosure: APPLE-SA-03-24-2026-7 watchOS 26.4 Full Disclosure: APPLE-SA-03-24-2026-6 tvOS 26.4 Full Disclosure: APPLE-SA-03-24-2026-5 macOS Sonoma 14.8.5 Full Disclosure: APPLE-SA-03-24-2026-4 macOS Sequoia 15.7.5 Full Disclosure: APPLE-SA-03-24-2026-3 macOS Tahoe 26.4 APPLE-SA-03-24-2026-2 iOS 18.7.7 and iPadOS 18.7.7 APPLE-SA-03-24-2026-1 iOS 26.4 and iPadOS 26.4
SSRF in Anthropic mcp-server-fetch and Microsoft playwright-mcp — publicly disclosed via GitHub issues
2026-05-26 · via Full Disclosure
fulldisclosure logo

Full Disclosure mailing list archives


From: outreach () posentia net
Date: Mon, 25 May 2026 20:10:43 +0000

-----BEGIN SECURITY ADVISORY-----

Title: Server-Side Request Forgery (SSRF) in Anthropic mcp-server-fetch and Microsoft playwright-mcp
Author: Syed Anas Mohiuddin <anasmohiuddinsyed () gmail com>
Date: May 25, 2026
CVSS: 7.5 (HIGH) — AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
References: Already public via GitHub issues (see below)

== AFFECTED PRODUCTS ==

1. Anthropic mcp-server-fetch (modelcontextprotocol/servers)
   All versions as of May 2026
   GitHub: https://github.com/modelcontextprotocol/servers
   Public issues: #4116, #4143, #4205

2. Microsoft playwright-mcp
   All versions as of May 2026
   GitHub: https://github.com/microsoft/playwright-mcp
   Public issue: #1626

== VULNERABILITY DESCRIPTION ==

Both MCP servers accept arbitrary URLs passed by the AI agent/client without
any allowlist enforcement, IP range blocking, or internal network filtering.
This enables Server-Side Request Forgery (SSRF) attacks via prompt injection:

Attack chain:
  1. Attacker embeds malicious instruction in a webpage
  2. AI agent fetches the page via mcp-server-fetch or playwright-mcp
  3. Embedded instruction redirects the agent to fetch the cloud metadata endpoint
  4. Agent calls fetch_url("http://169.254.169.254/latest/meta-data/iam/security-credentials/";)
  5. IMDSv1 returns IAM credentials without authentication
  6. Agent includes credentials in its next response
  7. Credentials exfiltrated

Additional finding in mcp-server-fetch:
The get_prompt handler calls fetch_url() directly without invoking
check_may_autonomously_fetch_url(), bypassing the robots.txt autonomy guard
through a structurally distinct code path (logic bypass).

== DISCOVERY ==

Found using mcp-safeguard, an open-source automated security scanner for MCP servers.
pip install mcp-safeguard
https://pypi.org/project/mcp-safeguard/

Scanning 54 production MCP servers: 27.8% had HIGH/CRITICAL findings.
8/54 (14.8%) confirmed SSRF. 7/54 credential exposure.

== DISCLOSURE TIMELINE ==

May 2026: Findings discovered via mcp-safeguard
May 2026: Reported to Anthropic Security (security () anthropic com)
May 2026: Reported to Microsoft MSRC (secure () microsoft com)
May 2026: Issues already publicly visible on GitHub (see References above)
May 2026: Public advisory posted to Full Disclosure

== MITIGATIONS ==

For MCP server operators:
- Enforce URL allowlists (only fetch from approved domains)
- Block RFC1918 and link-local ranges at the application layer
- Use IMDSv2 (requires session token; not fetchable via simple HTTP)
- Pin resolved IPs before making TCP connections (prevents DNS rebinding)
- Validate redirect destinations before following

For AI agent deployments:
- Review all MCP servers in your stack using mcp-safeguard
- Apply network-level SSRF mitigations (cloud security groups, VPC policies)
- Disable IMDSv1 on all EC2 instances

== REFERENCES ==

Public GitHub issues (already disclosed):
- https://github.com/modelcontextprotocol/servers/issues/4116
- https://github.com/modelcontextprotocol/servers/issues/4143
- https://github.com/modelcontextprotocol/servers/issues/4205
- https://github.com/microsoft/playwright-mcp/issues/1626

Protocol Pivoting preprint (cross-protocol attack escalation):
https://zenodo.org/records/20371152

mcp-safeguard (detection tool):
https://pypi.org/project/mcp-safeguard/

-----END SECURITY ADVISORY-----

Syed Anas Mohiuddin
AI Security Researcher
anasmohiuddinsyed () gmail com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • SSRF in Anthropic mcp-server-fetch and Microsoft playwright-mcp — publicly disclosed via GitHub issues outreach (May 25)