Executive brief
Scrapling-fetch-mcp is an MCP server that helps AI assistants retrieve text content from websites protected by anti-automation measures. The server contains a vulnerability in its URL fetching function that allows attackers to perform server-side request forgery (SSRF) attacks, potentially enabling access to internal network resources or local files. This could allow an attacker to read arbitrary local files or probe internal systems accessible from the server.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the s_fetch_page and s_fetch_pattern functions within src/scrapling_fetch_mcp/_fetcher.py. The root cause is insufficient URL scheme validation, allowing non-HTTP/HTTPS schemes (such as file://) to be passed to the fetcher, enabling arbitrary local file reads or internal network access. The attack can be launched remotely by an authenticated user or client providing a crafted URL to the fetcher. An attacker can exploit this to read sensitive local files or make requests to internal services. The vulnerability was patched in version 0.2.3 (commit 9f6f34e) by restricting URL schemes to http and https only before the request reaches the fetcher.
Affected products
- cyberchitta scrapling-fetch-mcp up to 0.2.2
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: patch commit 9f6f34e92c55c3d95566ad9c62aca7327d24533a restricts fetch URLs to http/https schemes; available in version 0.2.3