The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
References
Configurations
No configuration.
History
09 Feb 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 09:16
Updated : 2026-02-09 16:08
NVD link : CVE-2026-25904
Mitre link : CVE-2026-25904
CVE.ORG link : CVE-2026-25904
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
