CVE-2026-74858

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 16:17

Updated : 2026-08-20 12:48


NVD link : CVE-2026-74858

Mitre link : CVE-2026-74858

CVE.ORG link : CVE-2026-74858


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)