Junglewise Threat Intelligence

CVE-2026-74858: jae-jae fetcher-mcp server-side request forgery in URL validation

CVE-2026-74858 · Severity: medium · CVSS 6.3 · Published 2026-08-17

Executive brief

fetcher-mcp is an MCP server that fetches and processes web page content using Playwright. A vulnerability in the fetch_url and fetch_urls functions allows attackers to make requests to internal network addresses (loopback, private ranges, cloud metadata endpoints) and retrieve the responses, potentially exposing sensitive configuration data or internal service information without authentication.

Technical details

The vulnerability is a server-side request forgery (SSRF) in the URL validation logic of the fetch_url and fetch_urls functions. The vulnerable component only validates that URLs use http:// or https:// schemes via validateUrlProtocol(), but fails to reject requests to loopback addresses (127.0.0.1), RFC1918 private ranges, link-local addresses, or cloud metadata endpoints before passing the URL to Playwright's page.goto(). An unauthenticated remote attacker can invoke fetch_url or fetch_urls with a crafted URL targeting internal services (e.g., http://127.0.0.1:33257 or AWS metadata endpoints at 169.254.169.254) and receive the response content, enabling reconnaissance of internal infrastructure and potential credential theft. No patch has been released as of the advisory date.

Affected products

  • jae-jae fetcher-mcp up to 0.3.9

Timeline

  • 2026-08-17: disclosed: CVE-2026-74858 published
  • 2026-06-30: other: Vulnerability reported via GitHub issue #37

References