Junglewise Threat Intelligence

CVE-2026-15750: MasterGo Magic MCP SSRF in mcp__getComponentLink

CVE-2026-15750 · Severity: medium · CVSS 6.3 · Published 2026-07-14

Technologies: MasterGo Magic-Mcp. Vendors: MasterGo.

Executive brief

MasterGo Magic MCP is a tool used to connect MasterGo design software with AI models. A security flaw allows an attacker to trick the server into making unauthorized web requests to internal systems or cloud metadata services. This could lead to the exposure of sensitive internal data, such as cloud credentials or private administrative interfaces, which are normally protected from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `mcp__getComponentLink` tool within `src/tools/get-component-link.ts`. The `url` argument is validated only as a generic string via `z.string()` and is passed directly to an HTTP GET request without scheme or hostname restrictions. An attacker can provide arbitrary URLs, including those for local services (localhost) or cloud metadata endpoints (e.g., 169.254.169.254), and receive the full response body. This is a non-blind SSRF primitive that can be triggered by any MCP client or prompt-injected agent. As of the advisory date, the project has not released a patch.

Affected products

  • mastergo-design mastergo-magic-mcp up to 0.2.0

Timeline

  • 2026-05-29: disclosed: Vulnerability reported to the vendor via GitHub issue.
  • 2026-07-14: advisory: CVE-2026-15750 published.

References

Related threats