Junglewise Threat Intelligence

CVE-2026-19770: FeedMob fm-mcp-servers server-side request forgery in download endpoint

CVE-2026-19770 · Severity: medium · CVSS 5.3 · Published 2026-08-14

Executive brief

FeedMob's fm-mcp-servers is a Model Context Protocol server that provides tools for accessing Smadex reporting data. An attacker with local access can exploit a server-side request forgery (SSRF) vulnerability in the download endpoint to make the server send HTTP requests to arbitrary destinations, including internal networks or localhost services, potentially exposing sensitive data or enabling lateral movement.

Technical details

The vulnerability exists in the downloadReport function of src/smadex-reporting/src/index.ts, which accepts a downloadUrl parameter with only basic string validation (z.string()) and immediately passes it to the fetch() call without URL format validation or destination allowlisting. The vulnerable component is the get_smadex_report MCP tool, which exposes this function to callers. An attacker with local access to invoke the MCP tool can craft an arbitrary URL pointing to internal services, private networks, or localhost, forcing the server to make requests on their behalf. The attack requires local environment access to invoke the tool; however, the exploit is publicly available. No patch is currently available as the project has not responded to the early disclosure.

Affected products

  • FeedMob fm-mcp-servers 0.0.3

Timeline

  • 2026-06-25: disclosed: Vulnerability reported via GitHub issue #198
  • 2026-08-14: advisory: CVE-2026-19770 published

References