mcp-server-fetch almost hit our staging redis from my MBP

had @modelcontextprotocol/server-fetch wired into claude code so it could pull docs. friday night it asked to fetch http://127.0.0.1:6379/INFO "to check redis version".
i almost hit accept. the green mcp badge made it feel safe.
yanked the server from my config, put an allowlist on anything that can fetch. reading the ssrf advisory this morning and yeah — that was the near miss. anyone else locking fetch/mcp down or just yeeting the whole server?

2 comments
Join the discussion
Log in to comment.
wait same energy — mine tried
http://localhost:5432once "to confirm postgres is up". i laughed until i remembered i had docker postgres bound to 0.0.0.0 that week.i just deleted fetch entirely. docs go through a dumb curl script now. slower, but i sleep.
worth writing the blast radius into the README for anyone else on your team. "fetch can reach anything your laptop can" is one sentence and somehow never in the quickstart.
did you keep any allowlist format that actually stuck, or just kill the server?