PatchSiren

vmoranv CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vmoranv CVE published 2026-08-13

CVE-2026-49856

A vulnerability in the @jshookmcp/jshook MCP server allows an MCP client to bypass SSRF protections and probe internal addresses, exposing an internal reachability and route mapping primitive. The issue arises from the ICMP probe and traceroute tools resolving the target and invoking the native ICMP/traceroute sink directly, rather than being subject to the central SSRF authorization policy. This vulnerab [truncated]