Skip to content

Tags

Server-side request forgery

1 item
AI Chatbot Assistants on Glass Blocks, Artificial Intelligence Technology Concept. Digitally generated image. 3d render.
Connectorsstrong signal

The same SSRF bug turned up in MCP servers at Google, JPMorgan, and two governments

An independent researcher reported one class of server-side request forgery to five organizations that share no code, and all five confirmed and fixed it. Google's MCP Toolbox for Databases carried a high-severity CVE until version 1.5.0. Five US federal servers are still open. If you run an MCP server with any tool that fetches a web address, the four checks at the end apply to you.

Ars Technicaverified