HIGH
mcp-use
CVE published 2026-08-27
CVE-2026-81091
A vulnerability in the proxy middleware of mcp-use's inspector allows an attacker to make the server issue requests to addresses reachable only from the host it runs on and read the responses. This is due to the lack of proper validation of the target URL, which can be supplied by the caller through the X-Target-URL header or the __mcp_target parameter.