CVE-2026-7729Disclosure

LOWCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-04: 4Active Exploitation · 2026-05-04: 1Technical Details · 2026-05-04: 305-04
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting pixelsock directus-mcp (CVE-2026-7729) https://vuldb.com/vuln/360904/cti

    Post summary

    The text suggests that CVE-2026-7729 is currently being targeted by attackers in the wild.

    0101067
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7729 A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Pe… https://www.cve.org/CVERecord?id=CVE-2026-7729

    Post summary

    The passage announces CVE-2026-7729, a flaw found in pixelsock directus-mcp 1.0.0 that affects the validateUrl function within index.ts, with no evidence of PoC, exploitation or patch information.

    00010181
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7729 A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Pe… https://www.cve.org/CVERecord?id=CVE-2026-7729 ----- Traducción: CVE-2026-7729 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-7729, a flaw in pixelsock directus-mcp 1.0.0 affecting the validateUrl function, with no PoC, exploit, or patch details provided.

    0000030
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7729 Server-Side Request Forgery in Pixelsock Directus-MCP 1.0.0 validateUrl Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7729

    Post summary

    CVE-2026-7729 is reported as a Server‑Side Request Forgery vulnerability in Pixelsock Directus‑MCP 1.0.0’s validateUrl function, but no PoC, exploit code, or patch details are provided.

    0000055
    4.0K followersView on X

Explore more