Skip to content

MCPA-2025-0013

mediumssrf

mcp-fetch-server SSRF via private-IP validation bypass (CVE-2025-65513)

fetch-mcp (npm: mcp-fetch-server) versions through 1.0.2 fail to properly validate private IP addresses in their is_ip_private() check, allowing server-side request forgery that reaches internal network resources through the server's URL-fetching tools.

Affected packages

EcosystemPackageAffected versions
npmmcp-fetch-server
>= 0, <= 1.0.2
No patched version listed at time of advisory publication; restrict egress or remove the server.

Identifiers

CVE-2025-65513GHSA-8fxj-2g9q-8fjwCWE-918

References

Timeline

  • Published: 2025-12-09

← All advisories