CVE-2026-81848: cyberchitta scrapling-fetch-mcp _fetcher.py s_fetch_pattern server-side request forgery
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function sfetchpage/sfetchpattern of the file src/scraplingfetchmcp/fetcher.py. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. Upgrading to version 0.2.3 is sufficient to resolve this issue. This patch is called 9f6f34e92c55c3d95566ad9c62aca7327d24533a. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cyberchitta scrapling-fetch-mcpto a version that resolves this vulnerability.Fixed in 0.2.3Patch 9f6f34e92c55c3d95566ad9c62aca7327d24533a
Event History
Frequently Asked Questions
Which versions need remediation?
Versions up to and including 0.2.2 are affected. Upgrade scrapling-fetch-mcp to version 0.2.3, which includes patch 9f6f34e92c55c3d95566ad9c62aca7327d24533a.
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the provided severity vector indicates low privileges and user interaction are required. Successful exploitation can cause the server to make attacker-influenced requests.