CVE-2026-104120: SSRF in MCP’s official mcp-server-fetch, fix PR still unmerged
NVD published CVE-2026-104120 (CVSS 7.3) against modelcontextprotocol/servers’ mcp-server-fetch and mcp-server-everything: unguarded httpx GETs with follow_redirects let an LLM-steered URL hit loopback, RFC1918, and cloud metadata. A private-IP/redirect-guard PR (#4890) has been open since Sept 28 and is still an unmerged draft—fence egress yourself until it lands.