CVE-2026-39885: Agentfront @frontmcp/adapters
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. This enables Server-Side Request Forgery (SSRF) and local file read attacks when processing untrusted OpenAPI specifications. This vulnerability is fixed in 2.3.0.
Affected products
- Agentfront @frontmcp/adapters: before 1.0.4 (fixed in 1.0.4)
- Agentfront @frontmcp/sdk: before 1.0.4 (fixed in 1.0.4)
- Agentfront Frontmcp: before 1.0.4 (fixed in 1.0.4)
- Frontmcp Mcp-From-Openapi: before 2.3.0 (fixed in 2.3.0)
Published 2026-04-08. Last modified 2026-07-24.