CVE-2026-74858
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Aug 17, 2026
Vendor
unknown
Description
A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.