Executive brief
mcpilot is a tool used for managing Model Context Protocol (MCP) API calls. A security vulnerability allows remote attackers to trick the server into making unauthorized requests to internal systems or external websites. This could lead to the exposure of sensitive internal data or allow an attacker to interact with private services that are not normally accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in horizon921 mcpilot 0.1.0 within the 'MCP API Call Endpoint'. The vulnerability is located in the file 'client/src/app/api/mcp/call/route.ts' where the 'serverBaseUrl' argument is processed without adequate validation. A remote attacker can manipulate this argument to force the application to perform outbound HTTP GET and POST requests to arbitrary targets, including localhost, private RFC1918 networks, and cloud metadata services. This occurs because the 'detectServerAndGetConfig' function and subsequent 'fetch' calls do not restrict the scheme, hostname, or port of the target URL. As of the advisory date, no official patch has been released by the maintainer.
Affected products
- horizon921 mcpilot 0.1.0
Timeline
- 2026-04-20: other: Vulnerability discovered by researcher
- 2026-05-11: disclosed: Issue reported to developer via GitHub
- 2026-06-01: advisory: CVE published