Loading market data...
← Back to CVE feed

CVE-2026-86122

MEDIUM CVSS 5.0 View on NVD ↗

Description

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Published: Sep 05, 2026 10:16 UTC Modified: Sep 05, 2026 10:16 UTC