CVE-2026-74858

Summary

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
jae-jaefetcher-mcp0.3.0affected
jae-jaefetcher-mcp0.3.1affected
jae-jaefetcher-mcp0.3.2affected
jae-jaefetcher-mcp0.3.3affected
jae-jaefetcher-mcp0.3.4affected
jae-jaefetcher-mcp0.3.5affected
jae-jaefetcher-mcp0.3.6affected
jae-jaefetcher-mcp0.3.7affected
jae-jaefetcher-mcp0.3.8affected
jae-jaefetcher-mcp0.3.9affected

Weaknesses

  • CWE-918: Server-Side Request Forgery

References