CVE-2025-65513: Zcaceres Fetch Mcp Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.

Affected products

  • Zcaceres Fetch Mcp Server: up to and including 1.0.2

Published 2025-12-09. Last modified 2026-06-17.