Same SSRF flaw found in MCP servers from Google, Anthropic, Microsoft and Weaviate
A security researcher discovered an identical Server-Side Request Forgery (SSRF) vulnerability in Model Context Protocol servers built independently by Google, Anthropic, Microsoft, and Weaviate across the first nine months of 2026. All four vendors shared a common flawed assumption: that a URL parameter supplied to their MCP servers could be trusted, when in reality any input processed by a language model must be treated as potentially attacker-controlled. Because MCP servers act on real-world resources — fetching web pages, querying databases, or driving browsers — a malicious URL injected via prompt manipulation could redirect requests to internal networks, metadata endpoints, or admin panels. Google's flaw was assigned CVE-2026-14540 with a CVSS v4.0 score of 8.0 (High) and was patched in v1.5.0, while Anthropic's and Microsoft's servers lacked allowlists and failed to block private or link-local IP ranges. The researcher noted the root cause was not a coding error unique to any one team, but a shared architectural misconception about the trust boundary between language models and the servers they control.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in