
Connectorsstrong signal
The same SSRF bug turned up in MCP servers at Google, JPMorgan, and two governments
An independent researcher reported one class of server-side request forgery to five organizations that share no code, and all five confirmed and fixed it. Google's MCP Toolbox for Databases carried a high-severity CVE until version 1.5.0. Five US federal servers are still open. If you run an MCP server with any tool that fetches a web address, the four checks at the end apply to you.
Ars Technicaverified