« Volver al listado

CVE-2026-39885

Estado: AnalizadaAlta (7.5)—

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. This enables Server-Side Request Forgery (SSRF) and local file read attacks when processing untrusted OpenAPI specifications. This vulnerability is fixed in 2.3.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Explotación remota sin privilegios (AV:N/PR:N) mediante especificación OpenAPI maliciosa. SSRF hacia endpoints internos/metadata (T1090) y lectura de ficheros locales (T1005) por falta de restricciones de URL en json-schema-ref-parser.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-39885",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-39885",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-09T14:53:12.471902Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "agentfront",
          "product": "frontmcp",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.0.4"
            }
          ]
        },
        {
          "vendor": "@frontmcp",
          "product": "adapters",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.0.4"
            }
          ]
        },
        {
          "vendor": "@frontmcp",
          "product": "sdk",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.0.4"
            }
          ]
        },
        {
          "vendor": "frontmcp",
          "product": "mcp-from-openapi",
          "versions": [
            {
              "status": "affected",
              "version": "<  2.3.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-08T21:17:00.833",
  "references": [
    {
      "url": "https://github.com/agentfront/frontmcp/releases/tag/v1.0.4",
      "tags": [
        "Product"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/agentfront/frontmcp/security/advisories/GHSA-v6ph-xcq9-qxxj",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/agentfront/frontmcp/security/advisories/GHSA-v6ph-xcq9-qxxj",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. This enables Server-Side Request Forgery (SSRF) and local file read attacks when processing untrusted OpenAPI specifications. This vulnerability is fixed in 2.3.0."
    },
    {
      "lang": "es",
      "value": "FrontMCP es un framework TypeScript-first para el Protocolo de Contexto de Modelo (MCP). Antes de la versión 2.3.0, la biblioteca mcp-from-openapi utiliza @apidevtools/json-schema-ref-parser para desreferenciar punteros $ref en especificaciones OpenAPI sin configurar ninguna restricción de URL o resolutores personalizados. Una especificación OpenAPI maliciosa que contenga valores $ref que apunten a direcciones de red internas, puntos finales de metadatos en la nube o archivos locales hará que la biblioteca obtenga esos recursos durante la llamada a initialize(). Esto permite ataques de falsificación de petición del lado del servidor (SSRF) y de lectura de archivos locales al procesar especificaciones OpenAPI no confiables. Esta vulnerabilidad se corrigió en la versión 2.3.0."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:agentfront:\\@frontmcp\\/adapters:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4359FEB-443B-4810-836F-17CF222E59A5",
              "versionEndExcluding": "1.0.4"
            },
            {
              "criteria": "cpe:2.3:a:agentfront:\\@frontmcp\\/sdk:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "944403B2-61F9-49E2-8E1D-E8A34313DCEA",
              "versionEndExcluding": "1.0.4"
            },
            {
              "criteria": "cpe:2.3:a:agentfront:frontmcp:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A711248-2B16-4ECA-878A-5CEA5274AB98",
              "versionEndExcluding": "1.0.4"
            },
            {
              "criteria": "cpe:2.3:a:frontmcp:mcp-from-openapi:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA827C0B-761C-4BC3-B9BD-E06918698B32",
              "versionEndExcluding": "2.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}