Executive brief
Apache SkyWalking MCP is a component used for managing service mesh configurations. A security vulnerability allows an attacker to trick the server into making unauthorized network requests by providing a malicious URL in a specific header. This could allow an attacker to access internal data or services that are not intended to be exposed to the outside world.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Apache SkyWalking MCP server (specifically version 0.1.0). The vulnerability is rooted in the improper validation of the 'SW-URL' HTTP header, which the server uses to initiate outbound requests. An authenticated attacker with network access can supply a malicious URL in this header, causing the server to perform requests to arbitrary internal or external destinations. This can lead to unauthorized information disclosure from internal services or limited modification of internal data. The issue is resolved in version 0.2.0.
Affected products
- Apache SkyWalking MCP 0.1.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory
- 2026-04-13: patched: Version 0.2.0 released