Executive brief
mcp-security is a framework that provides security and authorization support for AI models using the Model Context Protocol (MCP). A vulnerability exists where the system fails to verify web addresses provided by external sources, allowing an attacker to force the server to make unauthorized requests to internal systems or malicious websites. This could lead to the exposure of sensitive internal network information or unauthorized access to internal services, particularly in environments where Dynamic Client Registration is enabled.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the mcp-security framework due to a failure to implement mandatory URL validation as required by the Model Context Protocol (MCP) security specifications. When Dynamic Client Registration (DCR) is enabled, the framework processes untrusted URLs for OAuth-related discovery and metadata without verifying if the targets are internal or malicious. An unauthenticated remote attacker can exploit this by providing malicious MCP server metadata or authorization server URLs, causing the client to perform unauthorized network requests. This can lead to internal network scanning or information disclosure. The issue is fixed in version 0.1.9 by implementing proper URL filtering.
Affected products
- Spring AI Community mcp-security < 0.1.9
Timeline
- 2026-05-11: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date