CVE-2026-49857 PUBLISHED

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

Assigner: GitHub_M
Reserved: 01.06.2026 Published: 13.08.2026 Updated: 13.08.2026

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in assertSafeUrl() (src/security.ts) to block requests to private and loopback addresses. However, the isPrivateV6() function fails to detect IPv4-mapped IPv6 loopback addresses in their hex-normalized form. When an attacker supplies a URL such as http://[::ffff:127.0.0.1]:PORT/, the Node.js WHATWG URL parser silently normalizes the host to [::ffff:7f00:1]. Because net.isIPv4('7f00:1') returns false, the private-IP check is bypassed and the URL is passed to the browser or HTTP client, allowing the MCP tool to reach loopback services that are supposed to be blocked. The issue is exploitable under default configuration without any special environment variable. Version 3.0.1 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CVSS Score: 7.4

Product Status

Vendor ymw0407
Product auth-fetch-mcp
Versions
  • Version < 3.0.2 is affected

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE