Executive brief
a11y-mcp is a local accessibility server that processes web page requests on behalf of users or AI assistants. A server-side request forgery (SSRF) vulnerability allows an attacker who can invoke the tool to redirect the server to fetch arbitrary URLs—including internal services, metadata endpoints, or private networks—potentially exposing sensitive information or enabling lateral movement within a network.
Technical details
The vulnerability is a server-side request forgery (CWE-918) in the A11yServer function within src/index.js. The audit_webpage and get_summary MCP handlers accept a user-controlled URL parameter and pass it directly to Puppeteer's page.goto() function without validating, allowlisting, or sanitizing the destination. An attacker with the ability to invoke these MCP tools can cause the server to initiate HTTP requests to arbitrary internal or external resources, including loopback addresses, RFC 1918 private networks, and cloud metadata endpoints. The attack vector is local or through the MCP interface; no network access or special privileges are required beyond the ability to call the affected tool. The vulnerability was patched in version 1.0.6 (commit e3e11c9e8482bd06b82fd9fced67be4856f0dffc); upgrading is the recommended fix.
Affected products
- priyankark a11y-mcp up to 1.0.5
Timeline
- 2026-04-02: disclosed: Published in OSV and NVD
- 2026-04-02: patched: Version 1.0.6 released with patch e3e11c9e8482bd06b82fd9fced67be4856f0dffc