CVE-2026-81421: ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component rawsentryapi. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability can be exploited remotely without privileges or user interaction. An attacker can manipulate the endpoint argument handled by the raw_sentry_api component.
How likely is exploitation?
Public exploit code has been released, and the issue is rated as having low attack complexity. This increases the likelihood of attempted exploitation where the affected component is reachable remotely.
Is a fix available?
The provided information identifies version 0.4.0 as affected but does not provide a fixed version or mitigation. The project was notified through an issue report and had not responded at the time of publication.