CVE-2026-74858: Jae-Jae Fetcher-Mcp

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • Jae-Jae Fetcher-Mcp: version 0.3.0 only; version 0.3.1 only; version 0.3.2 only; version 0.3.3 only; version 0.3.4 only; version 0.3.5 only; …

Published 2026-08-17. Last modified 2026-08-20.