PT-2026-35531 · Unknown · Mcp-Url-Downloader

Smallw

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7158

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dmitryglhf mcp-url-downloader versions prior to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6
Description An issue in the validate url safe() function within the src/mcp url downloader/server.py file allows for server-side request forgery (SSRF), a flaw where an attacker can induce the server to make requests to an unintended location. This can be executed remotely by manipulating the url argument.
Recommendations Update to a version later than 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. As a temporary workaround, restrict access to the validate url safe() function to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7158
GHSA-H7XC-4MV8-59FJ

Affected Products

Mcp-Url-Downloader