CVE-2026-104120

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Full discourse1 post
  • IA en Bruto@IAenBruto

    CVE-2026-104120: `mcp-server-fetch` (reference MCP) GET sin fence a IPs privadas. NVD ayer; fix draft. Anti-hype: README ya avisaba local. Aviso ≠ control. La URL la arma el LLM. Tip: egress deny RFC1918/loopback/metadata. No esperes el patch. Revisá `mcp-server-everything`. https://t.co/ny2QO5uY6h

    2000061
    100 followersView on X

Explore more