Junglewise Threat Intelligence

CVE-2026-46341: Apify MCP server domain allowlist bypass in fetch-apify-docs

CVE-2026-46341 · Severity: medium · CVSS 6.1 · Published 2026-07-16

Vendors: npm.

Executive brief

The Apify Model Context Protocol (MCP) server, which allows AI agents to interact with web scraping and automation tools, contains a security flaw in how it restricts access to documentation. A flaw in the server's web address validation allows an attacker to trick the AI into visiting malicious websites instead of official documentation. This can lead to 'prompt injection,' where the AI follows hidden instructions from the malicious site, potentially resulting in unauthorized actions or the theft of sensitive access tokens.

Technical details

The 'fetch-apify-docs' tool in 'src/tools/common/fetch_apify_docs.ts' uses a flawed validation mechanism for its documentation allowlist. Instead of performing a proper URL hostname comparison, it uses 'String.startsWith()' to check if a URL begins with an allowed domain (e.g., 'https://docs.apify.com'). An attacker can bypass this check using specially crafted URLs like 'https://docs.apify.com.evil.com/' or 'https://docs.apify.com@evil.com/'. When the AI agent fetches content from these attacker-controlled URLs, the returned HTML is converted to markdown and fed to the LLM. This enables prompt injection attacks where the LLM may follow malicious instructions, such as leaking the '_meta.apifyToken' or performing unauthorized billable operations. The issue is fixed in version 0.9.21 by implementing strict hostname and protocol validation.

Affected products

  • Apify apify-mcp-server (actors-mcp-server) < 0.9.21

Timeline

  • 2026-05-01: disclosed: Vulnerability reported and fix proposed via PR #781
  • 2026-05-04: patched: Version 0.9.21 released
  • 2026-05-13: advisory: GitHub Security Advisory GHSA-jwp7-wg77-3w9v published
  • 2026-07-16: advisory: CVE-2026-46341 published to NVD

References

Related threats