MEDIUM
vmoranv
CVE published 2026-08-13
CVE-2026-49856
A vulnerability in the @jshookmcp/jshook MCP server allows an MCP client to bypass SSRF protections and probe internal addresses, exposing an internal reachability and route mapping primitive. The issue arises from the ICMP probe and traceroute tools resolving the target and invoking the native ICMP/traceroute sink directly, rather than being subject to the central SSRF authorization policy. This vulnerab [truncated]