Threat · curated 2 Oct 2026
NVD-CVE-2026-104120
First reported nist.gov
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-104120 affects a widely used Model Context Protocol fetch server, so an SSRF via its tool interface could let attackers pivot to internal resources through AI agents that rely on these MCP servers.
CVE-2026-104120 is a server-side request forgery (SSRF) vulnerability in the fetch_url function of modelcontextprotocol's mcp-server-fetch and mcp-server-everything (up to version 2026.6.4), where manipulation of the url/path argument in the Fetch Tool allows a remote attacker to coerce server-side requests. The exploit has been disclosed publicly and a fix pull request awaits acceptance; CVSS 4.0 rates it 5.5 (medium).