CVE-2026-80347: mcp-fetch through 1.6.3 Server-Side Request Forgery via Unstripped IPv6 Literal Brackets
mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, and then tests it with net.isIP. That call returns zero for a bracketed value, so the branch holding the private-address checks is skipped entirely. The guard falls back to resolving the hostname, the bracketed string is not a resolvable name, no addresses are returned, and the target is reported safe. The HTTP client then strips the brackets and connects. Because the address may be given in IPv4-mapped form, the same path reaches any IPv4 target the loopback and private checks were meant to exclude, including link-local metadata endpoints. isPrivateIPv6 also has no case for the ::ffff: prefix, so the mapped form would still pass even if the brackets were removed. The fetch target is supplied as a tool argument, so an attacker who can influence what the model requests can read internal responses back into the model context.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to be able to influence the fetch target supplied to mcp-fetch as a tool argument, such as by causing the model to request an attacker-chosen URL. No authentication, user interaction, or special privileges are indicated by the supplied severity vector.
What internal resources could be reached?
The bypass can reach IPv6 loopback and private addresses using bracketed IPv6 literals. IPv4-mapped IPv6 notation can also reach IPv4 targets that the guard was intended to block, including link-local metadata endpoints.
What is the impact if exploitation succeeds?
mcp-fetch can retrieve responses from internal services and return those responses into the model context. The provided data indicates high confidentiality impact, with no stated integrity or availability impact.
Which versions are affected?
The issue affects mcp-fetch through version 1.6.3. The provided information does not identify a fixed version.