Executive brief
HackMD MCP Server is a backend component that handles API requests for HackMD document management. An SSRF vulnerability in HTTP mode allows attackers to redirect API calls to internal network services, potentially accessing sensitive endpoints or bypassing firewall controls without authentication.
Technical details
The vulnerability is a Server-Side Request Forgery (CWE-918) affecting HackMD MCP versions 1.4.0 through 1.4.x. Attackers can inject arbitrary hackmdApiUrl values via HTTP headers (Hackmd-Api-Url) or base64-encoded JSON query parameters to force the server to make requests to attacker-controlled or internal network endpoints. The attack requires network access to the HTTP interface and no authentication. Exploitation allows reconnaissance of internal services, access to sensitive endpoints, and bypass of network access controls. The vulnerability has been patched in version 1.5.0; users should upgrade and configure ALLOWED_HACKMD_API_URLS environment variable to restrict endpoints.
Affected products
- HackMD MCP Server 1.4.0 to 1.4.x (fixed in 1.5.0)
Timeline
- 2025-09-15: disclosed
- 2025-09-15: patched: Version 1.5.0 released