OVERVIEW CVE-2026-39885 is a Server-Side Request Forgery (SSRF) vulnerability in the mcp-from-openapi library, a component of FrontMCP (a TypeScript framework for the Model Context Protocol), affecting versions prior to 2.3.0. The vulnerability exists in how the library processes OpenAPI specifications, specifically in its use of the @apidevtools/json-schema-ref-parser to dereference $ref pointers without implementing URL restrictions or custom resolvers. An attacker can craft a malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local file paths, which are fetched when the initialize() function is called. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), with a network-based attack vector requiring no authentication or user interaction. The attack is easy to execute with low complexity, enabling unauthorized information disclosure from confidential resources. The potential impact is significant, as attackers can access sensitive data from internal systems, cloud metadata services containing credentials, or local files on affected systems. The EPSS score of 0.000410000 indicates minimal current prevalence in active exploitation. EXPLOITATION STATUS No evidence of active exploitation has been reported, and the vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog. No public exploit code appears to be available, and community attention remains low. Organizations using FrontMCP versions prior to 2.3.0 should prioritize patching to mitigate the risk of SSRF attacks when processing untrusted OpenAPI specifications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.4CPE matchmatch criteria | cpe:2.3:a:agentfront:\@frontmcp\/adapters:*:*:*:*:*:node.js:*:* | ||
< 1.0.4CPE matchmatch criteria | cpe:2.3:a:agentfront:\@frontmcp\/sdk:*:*:*:*:*:node.js:*:* | ||
< 1.0.4CPE matchmatch criteria | cpe:2.3:a:agentfront:frontmcp:*:*:*:*:*:node.js:*:* | ||
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:frontmcp:mcp-from-openapi:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.