Executive brief
The auth-fetch-mcp library, which allows AI models to fetch and download web content, is vulnerable to a security flaw that lets an attacker access internal network resources. By providing specially crafted URLs, an attacker can force the server to retrieve sensitive data from private internal services or cloud metadata endpoints. This could lead to the theft of cloud credentials, exposure of internal database contents, or unauthorized access to local administrative interfaces.
Technical details
The `download_media` and `auth_fetch` tools in `auth-fetch-mcp` fail to validate user-provided URLs before dispatching requests via Playwright's `APIRequestContext.get` and `page.goto`. An attacker can provide loopback (127.0.0.1), link-local (169.254.169.254), or private-range IP addresses to reach services not intended for public exposure. In `download_media`, the response body is written to a user-controlled `output_dir` without path sanitization, enabling arbitrary disk writes. In `auth_fetch`, the DOM of internal pages is returned directly to the caller. This allows for cloud credential theft via IMDS endpoints and internal service enumeration. Version 3.0.1 contains patches to address these issues.
Affected products
- ymw0407 auth-fetch-mcp <= 3.0.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory
- 2026-05-19: patched: Version 3.0.1 released