MEDIUM
TencentCloudBase
CVE published 2026-04-28
CVE-2026-7221
A server-side request forgery vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. The open-url API Endpoint's function openUrl in mcp/src/interactive-server.ts is affected by manipulating the req.body.url argument. This issue can be addressed by upgrading to version 2.17.1. The patch is identified as 3f678a1e7bd400cd76469d61024097d4920dc6b5. Users should review their deployments and ap [truncated]