← voltar
CVE-2026-25904

Overly permissive Deno configuration in mcp-run-python leads to SSRF

CVSS 5.8 MEDIUMEPSS 0.2%CWE-918
The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Produtos afetados
mcp-run-python

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →