GHSA-c33j-cj33-6649MediumCVSS 6.3

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function...

Published
August 17, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

🔗 References (8)