Executive brief
The Apify Model Context Protocol (MCP) server is a library used to integrate Apify's web automation tools with AI models. A security flaw allows an attacker to create a malicious 'Actor' that, when interacted with by a user, redirects the user's connection to an attacker-controlled server. This results in the silent theft of the user's Apify API token, which gives the attacker full control over the victim's account, including access to private data and the ability to incur compute charges.
Technical details
The vulnerability exists in the `getActorMCPServerURL()` function within `src/mcp/actors.ts`, where the server constructs standby URLs by naively concatenating a trusted base URL with an attacker-controlled `webServerMcpPath`. By providing a path starting with an `@` character (e.g., `@attacker.example/mcp`), an attacker can exploit the WHATWG URL parsing logic to treat the original trusted host as userinfo and redirect the request to an arbitrary hostname. Because the MCP client unconditionally attaches the victim's `Authorization: Bearer` token to all outbound requests without verifying the destination origin, the token is leaked to the attacker's server. This affects tools like `call-actor` and `fetch-actor-details`. The issue is fixed in version 0.10.11 by implementing origin validation and clearing URL credentials.
Affected products
- Apify @apify/actors-mcp-server < 0.10.11
Timeline
- 2026-05-28: disclosed
- 2026-07-01: advisory