Aianytime · Awesome-Mcp-Server · CVE-2026-14748
**Name of the Vulnerable Software and Affected Versions**
AIAnytime Awesome-MCP-Server versions up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab
**Description**
A flaw in the `mcp-wiki/wiki-summary` component, specifically within the `mcp-wiki/src/mcp wiki/server.py` file, allows for server-side request forgery (SSRF). This occurs when the `url` argument is manipulated, enabling a remote attacker to initiate unauthorized requests from the server.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.