CVE-2026-34884 PUBLISHED

Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server

Assigner: apache
Reserved: 31.03.2026 Published: 18.08.2026 Updated: 18.08.2026

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.

This issue affects Apache SkyWalking MCP: 0.1.0.

Users are recommended to upgrade to version 0.2.0, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache SkyWalking MCP
Versions Default: unaffected
  • Version 0.1.0 is affected

Credits

  • Andrea Cosentino <ancosen@gmail.com> reporter

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE