PT-2026-45869 · Unknown · Blender-Mcp

Skywings

·

Published

2026-06-02

·

Updated

2026-06-04

·

CVE-2026-10662

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ahujasid blender-mcp versions prior to 5b37be25242e73dc4cf1328974d30458b9e5d67e
Description Server-side request forgery can be executed remotely via the ZIP File Handler component. The issue exists in the requests.get() function within the src/blender mcp/server.py file, where manipulation of the zip file url argument allows the attack.
Recommendations Apply patch 5b37be25242e73dc4cf1328974d30458b9e5d67e. As a temporary workaround, restrict access to the ZIP File Handler component or avoid using the zip file url argument in the requests.get() function.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10662

Affected Products

Blender-Mcp