CVE-2026-7729

A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

04 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-04 05:16

Updated : 2026-05-04 15:18


NVD link : CVE-2026-7729

Mitre link : CVE-2026-7729

CVE.ORG link : CVE-2026-7729


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)