Junglewise Threat Intelligence

CVE-2026-19957: Graphlit graphlit-mcp-server SSRF in retrieveImages endpoint

CVE-2026-19957 · Severity: medium · CVSS 6.3 · Published 2026-08-16

Executive brief

Graphlit's MCP (Model Context Protocol) server is an integration layer that connects AI assistants like Claude and Gemini to a knowledge management platform. The retrieveImages function fails to validate user-supplied URLs before fetching them on the server, allowing attackers to make the server fetch arbitrary internal resources, metadata endpoints, or private data—potentially exposing sensitive information or enabling lateral network attacks.

Technical details

The vulnerability is a classic server-side request forgery (SSRF) in the retrieveImages tool of graphlit-mcp-server v1.0.1 (src/tools.ts). The tool accepts a user-supplied url parameter as a plain string with no validation of the destination host, IP range, or protocol, then passes it directly to Node.js's global fetch() function. Unlike other URL-based tools in the same codebase (ingestUrl, describeImageUrl) that delegate HTTP requests to the Graphlit cloud API, retrieveImages executes the fetch locally on the server host. An attacker can supply internal URLs (e.g., cloud metadata endpoints, private IP ranges, localhost services) and retrieve the full response body, which is then Base64-encoded and sent to the Graphlit platform. The vulnerability requires network access to the MCP server but no authentication; it is remotely exploitable and has a published proof-of-concept. No patch has been released as of the advisory date.

Affected products

  • Graphlit graphlit-mcp-server 1.0.1

Timeline

  • 2026-08-16: disclosed
  • other: Exploit publicly available

References