Skip to content

MCPA-2026-0090

mediumssrfCVSS 6.3

alibabacloud-dataworks-mcp-server ReadResource server-side request forgery (CVE-2026-19339)

alibabacloud-dataworks-mcp-server (npm): the MCP ReadResource handler in src/resources/initResources.ts passes any request.params.uri that starts with 'http' directly to fetch() and returns the response body, with no allowlist or network-range validation, so an MCP client (or a prompt-injected tool call) can make the server request loopback, private-network, or cloud-metadata URLs from the server's network position and read the responses (SSRF). The upstream issue is open and the vulnerable code is still present in npm latest 1.0.45 (verified by unpacking the published tarball), so this is recorded as last_affected 1.0.45.

Affected packages

EcosystemPackageAffected versions
npmalibabacloud-dataworks-mcp-server
>= 0, <= 1.0.45

Identifiers

CVE-2026-19339GHSA-jgm8-jqmm-5rc5CWE-918

References

Timeline

  • Published: 2026-08-09

← All advisories