Same SSRF flaw found in MCP servers from Google, Anthropic, Microsoft, and Weaviate
A security researcher discovered an identical Server-Side Request Forgery (SSRF) vulnerability in Model Context Protocol servers independently built by four major vendors — Google, Anthropic, Microsoft, and Weaviate — over the first nine months of 2026. The shared flaw stemmed from a common false assumption: that a URL configured or supplied by an operator was inherently trustworthy, leaving model-supplied URLs unvalidated against internal IP ranges, loopback addresses, and redirect chains. Because MCP servers act on structured input from language models, any attacker who can influence what a model reads — via a prompt-injected webpage, document, or database row — can effectively control the server's outbound requests. Google's fix was merged in June 2026 and released as MCP Toolbox v1.5.0, with the issue assigned CVE-2026-14540 at CVSS 8.0 High. The pattern across four separate codebases, languages, and review cultures suggests the vulnerability reflects a systemic industry-wide misconception about trust boundaries in AI-integrated server architectures.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in