{"id":"CVE-2026-50143","summary":"Actor MCP path authority injection leaks Apify token","details":"The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor publisher to use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp tool-loading paths pass this URL to transports in src/mcp/client.ts that attach the victim Authorization bearer token, exposing the Apify API token and enabling access to Actors, stored data, and billable compute. A victim must invoke or inspect the attacker-controlled Actor. This issue is fixed in version 0.10.11.","aliases":["GHSA-6gr2-qh89-hxwm"],"modified":"2026-08-20T03:54:24.376803903Z","published":"2026-08-18T17:51:18.888Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50143.json"},"references":[{"type":"WEB","url":"https://github.com/apify/apify-mcp-server/releases/tag/v0.10.11"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50143.json"},{"type":"ADVISORY","url":"https://github.com/apify/apify-mcp-server/security/advisories/GHSA-6gr2-qh89-hxwm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50143"},{"type":"FIX","url":"https://github.com/apify/apify-mcp-server/commit/ef686d77da3d3c86c30b2ae24218d756aa38e09c"},{"type":"FIX","url":"https://github.com/apify/apify-mcp-server/pull/927"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apify/apify-mcp-server","events":[{"introduced":"0"},{"fixed":"ef686d77da3d3c86c30b2ae24218d756aa38e09c"},{"fixed":"7e054ac43c9258a78741f44c2ae2fb9c32336b4f"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.10.11"}]}}],"versions":["v0.10.10","v0.10.9","v0.10.8","v0.10.6","v0.9.16","v0.10.5","v0.10.4","v0.10.3","v0.10.2","v0.10.1","v0.10.0","v0.9.22","v0.9.21","v0.9.20","v0.9.19","v0.9.18","v0.9.17","v0.9.15","v0.9.14","v0.9.13","v0.9.12","v0.9.11","v0.9.10","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.6","v0.8.4","v0.8.3","v0.8.2","v0.8.1","v0.7.4","v0.7.1","v0.7.0","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.1","v0.6.4","v0.6.3","v0.6.2","v0.6.0","v0.5.9","v0.5.8","v0.5.6","v0.5.5","v0.5.2","v0.5.1","v0.5.0","v0.4.28","v0.4.27","v0.4.26","v0.4.25","v0.4.24","v0.4.23","v0.4.21","v0.4.20","v0.4.19","v0.4.18","v0.4.17","v0.4.16","v0.4.14","v0.4.13","v0.4.12","v0.4.10","v0.4.9","v0.4.7","v0.4.5","v0.4.4","v0.4.3","v0.4.1","v0.4.0","v0.3.9","v0.3.8","v0.3.7","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.2.16","v0.2.15","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.30","v0.1.29","v0.1.28","v0.1.27","v0.1.26","v0.1.25","v0.1.24","v0.1.23","v0.1.22","v0.1.21","v0.1.20","v0.1.19","v0.1.18","v0.1.17","v0.1.16","v0.1.15","v0.1.14","v0.1.13","v0.1.12","v0.1.11","v0.1.10","v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50143.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}