Junglewise Threat Intelligence

CVE-2026-16328: HashiCorp consul-mcp-server SSRF and token exfiltration

CVE-2026-16328 · Severity: high · CVSS 8.6 · Published 2026-07-29

Vendors: HashiCorp.

Executive brief

HashiCorp consul-mcp-server is a tool that allows AI agents to interact with Consul clusters. A vulnerability in this server allows a connected user to redirect the server's internal traffic to a malicious destination. This could result in the theft of sensitive Consul authentication tokens, potentially giving an attacker unauthorized access to the broader Consul environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in consul-mcp-server versions 0.1.0 through 0.1.3. The server fails to validate or restrict the Consul backend address when it is supplied via a client-provided request header. A remote, unauthenticated attacker can exploit this to override the configured Consul address, forcing the server to send API requests—including the configured Consul authentication token—to an attacker-controlled endpoint. This issue is fixed in version 0.1.4.

Affected products

  • HashiCorp consul-mcp-server 0.1.0 - 0.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched

References

Related threats