Threat · curated 2 Oct 2026

NVD-CVE-2026-104120

Coverage timeline

2 Oct 2026nist.gov

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-104120 affects a widely used Model Context Protocol fetch server, so an SSRF via its tool interface could let attackers pivot to internal resources through AI agents that rely on these MCP servers.

CVE-2026-104120 is a server-side request forgery (SSRF) vulnerability in the fetch_url function of modelcontextprotocol's mcp-server-fetch and mcp-server-everything (up to version 2026.6.4), where manipulation of the url/path argument in the Fetch Tool allows a remote attacker to coerce server-side requests. The exploit has been disclosed publicly and a fix pull request awaits acceptance; CVSS 4.0 rates it 5.5 (medium).