Activepieces: Server-side request forgery in MCP tool validation endpoint
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 84% de las CVE
explotación observada
noninguna fuente lo reporta
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
activepieces · activepiecesReferencias
https://github.com/activepieces/activepieces/commit/d385079cf4a9f35ddf61ba68ecda6ac8d64cf9e1https://github.com/activepieces/activepieces/pull/12721https://github.com/activepieces/activepieces/releases/tag/0.82.0https://github.com/activepieces/activepieces/security/advisories/GHSA-7qx9-q4xx-rh59