Junglewise Threat Intelligence

CVE-2026-14869: HashiCorp terraform-mcp-server SSRF in streamable-HTTP transport

CVE-2026-14869 · Severity: high · CVSS 8.6 · Published 2026-07-28

Technologies: HashiCorp Terraform-Mcp-Server. Vendors: HashiCorp.

Executive brief

HashiCorp terraform-mcp-server is a tool used to integrate Terraform with Model Context Protocol (MCP) clients, such as AI assistants. A security flaw in how the server handles web requests allows an unauthenticated attacker to trick the server into sending its sensitive authorization tokens to a server controlled by the attacker. This could lead to the full compromise of the Terraform Cloud or Enterprise environment connected to the server.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the streamable-HTTP transport of terraform-mcp-server. The vulnerability is caused by insufficient validation of client-supplied Terraform addresses when provided as an HTTP query parameter, even though the server correctly rejected such addresses when provided in HTTP headers. An unauthenticated remote attacker can supply a malicious URL via a query parameter, causing the server to send its configured bearer token to the attacker-controlled endpoint. This issue affects deployments using the streamable-HTTP listener; deployments using stdio mode exclusively are not impacted. The vulnerability is fixed in version 1.1.0.

Affected products

  • HashiCorp terraform-mcp-server 0.2.1 up to and including 1.0.0

Timeline

  • 2026-07-28: disclosed: Initial advisory published by HashiCorp
  • 2026-07-28: patched: Fixed in version 1.1.0

References

Related threats