MCPA-2026-0035
highssrfCVSS 8.3
meta-ads-mcp SSRF in upload_ad_image via unrestricted image_url fetch (CVE-2026-54549)
meta-ads-mcp (PyPI) before 1.0.115: the upload_ad_image MCP tool passes an attacker-controlled image_url directly to httpx.AsyncClient(follow_redirects=True).get() with no scheme, host, or IP validation, letting a caller (or a prompt-injected agent) make the server fetch arbitrary internal URLs, including cloud metadata endpoints. Fixed in 1.0.115.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | meta-ads-mcp | >= 0, < 1.0.115 |
Identifiers
CVE-2026-54549GHSA-45gf-fjxp-cjpqCWE-918
References
- advisory https://github.com/pipeboard-co/meta-ads-mcp/security/advisories/GHSA-45gf-fjxp-cjpq
- fix https://github.com/pipeboard-co/meta-ads-mcp/commit/7d9926336bbdac6285a988d043c4ccfe126c94c5
- web https://github.com/pipeboard-co/meta-ads-mcp/releases/tag/1.0.115
Timeline
- Published: 2026-07-17