MEDIUM
rowboatlabs
CVE published 2026-09-05
CVE-2026-86122
CVE-2026-86122 is a server-side request forgery vulnerability in Rowboat through version 0.9.1. The vulnerability allows authenticated users to configure arbitrary destinations for custom MCP server and webhook URLs, which can be exploited to perform server-side request forgery and enumerate internal network topology. This issue is particularly concerning for defenders responsible for Rowboat deployments, [truncated]