Executive brief
mcp-rdf-explorer is a Model Context Protocol server that fetches RSS/OPML feeds from URLs and extracts data. The vulnerability allows an attacker to supply arbitrary URLs that the server will fetch on their behalf, enabling access to internal services, cloud metadata endpoints, and sensitive information that should not be exposed to remote attackers.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the explore_url function of src/mcp-rdf-explorer/server.py. The url parameter is passed directly to Python's requests.get() without any validation—no scheme restrictions, domain allowlisting, IP-range filtering, or timeout enforcement. An MCP client can invoke the explore_url tool with a malicious URL pointing to internal services (localhost, private IP ranges) or cloud metadata endpoints, causing the server process to make HTTP GET requests to attacker-controlled or restricted destinations. The vulnerability is trivially exploitable via direct tool invocation or through prompt injection in agent workflows. No fix or patch is currently available from the vendor, which did not respond to early disclosure.
Affected products
- Model Context Protocol mcp-rdf-explorer 1.0.0
Timeline
- 2026-06-25: disclosed
- 2026-08-13: advisory