CVE-2026-7221Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.17.1 is able to address this issue. The patch is identified as 3f678a1e7bd400cd76469d61024097d4920dc6b5. It is recommended to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-28); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-28: 2Mentions · 2026-04-29: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 204-2804-29
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    ☁️ CVE-2026-7221 — A vulnerability in TencentCloudBase CloudBase‑MCP up to 2.17.0 affects openUrl; manipulating req.body.url can lead to remote SSRF. #CVE-2026-7221 #CloudBaseMCP #SSRF #Vulnerability #CWE918 https://nvd.nist.gov/vuln/detail/CVE-2026-7221

    Post summary

    The post announces a new SSRF vulnerability (CVE-2026-7221) in TencentCloudBase CloudBase‑MCP up to version 2.17.0, detailing how manipulating req.body.url can lead to remote server-side request forgery.

    2004069
    1.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7221 A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component op… https://www.cve.org/CVERecord?id=CVE-2026-7221 ----- Traducción: CVE-2026-7221 Se … http://infoflow.cloud`

    Post summary

    A vulnerability (CVE-2026-7221) was disclosed in TencentCloudBase CloudBase-MCP, affecting the openUrl function in interactive-server.ts up to version 2.17.0, with technical details and a link to the CVE record.

    0000049
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7221 A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component op… https://www.cve.org/CVERecord?id=CVE-2026-7221

    Post summary

    A new vulnerability, CVE-2026-7221, affecting the openUrl function in TencentCloudBase CloudBase-MCP's interactive-server module has been disclosed.

    00000179
    57.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7221 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7221 #CVE-2026-7221 #CVE #High #CyberSecurity #InfoSec https://t.co/7PnPy9oosj

    Post summary

    The tweet merely announces the existence of the CVE-2026-7221 with a severity rating, without providing technical details, PoC, exploitation claims, or mitigation information.

    0000060
    142 followersView on X

Explore more