{"id":"GHSA-8fxj-2g9q-8fjw","summary":"Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability","details":"fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.","aliases":["CVE-2025-65513"],"modified":"2025-12-10T17:41:16.608540Z","published":"2025-12-10T00:30:22Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-10T17:18:04Z","nvd_published_at":"2025-12-09T22:16:15Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65513"},{"type":"WEB","url":"https://github.com/Team-Off-course/MCP-Server-Vuln-Analysis/blob/main/CVE-2025-65513.md"},{"type":"PACKAGE","url":"https://github.com/zcaceres/fetch-mcp"},{"type":"WEB","url":"https://github.com/zcaceres/fetch-mcp/blob/c662c8ac300f715e414a64766cd95cc9ec60a1b3/src/Fetcher.ts#L20"},{"type":"WEB","url":"https://thorn-pheasant-6d8.notion.site/fetch-mcp-2853daf7b44180029ca5d56e03195736"}],"affected":[{"package":{"name":"mcp-fetch-server","ecosystem":"npm","purl":"pkg:npm/mcp-fetch-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-8fxj-2g9q-8fjw/GHSA-8fxj-2g9q-8fjw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}