Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v6ph-xcq9-qxxj | mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications |
Wed, 15 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentfront \@frontmcp\/adapters
Agentfront \@frontmcp\/sdk |
|
| CPEs | cpe:2.3:a:agentfront:\@frontmcp\/adapters:*:*:*:*:*:node.js:*:* cpe:2.3:a:agentfront:\@frontmcp\/sdk:*:*:*:*:*:node.js:*:* cpe:2.3:a:agentfront:frontmcp:*:*:*:*:*:node.js:*:* cpe:2.3:a:frontmcp:mcp-from-openapi:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Agentfront \@frontmcp\/adapters
Agentfront \@frontmcp\/sdk |
Thu, 09 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentfront
Agentfront frontmcp Frontmcp Frontmcp mcp-from-openapi |
|
| Vendors & Products |
Agentfront
Agentfront frontmcp Frontmcp Frontmcp mcp-from-openapi |
Wed, 08 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. This enables Server-Side Request Forgery (SSRF) and local file read attacks when processing untrusted OpenAPI specifications. This vulnerability is fixed in 2.3.0. | |
| Title | FrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T16:16:59.067Z
Reserved: 2026-04-07T20:32:03.010Z
Link: CVE-2026-39885
Updated: 2026-04-09T14:53:28.220Z
Status : Analyzed
Published: 2026-04-08T21:17:00.833
Modified: 2026-04-15T19:04:51.807
Link: CVE-2026-39885
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:27:16Z
Github GHSA