Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
consul-mcp-server vulnerable to server side request forgery leading to token exposure
Vulnerability Description
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
HashiCorp consul-mcp-server 服务端请求伪造漏洞
Vulnerability Description
HashiCorp consul-mcp-server是美国HashiCorp公司的一款服务端软件产品。 HashiCorp consul-mcp-server 0.1.3及之前版本存在服务端请求伪造漏洞,该漏洞源于未限制Consul后端地址的提供方式,允许连接的客户端通过请求头覆盖服务器配置的Consul地址,可能导致恶意客户端将服务器的Consul API流量重定向到攻击者控制的端点,从而泄露服务器配置的Consul令牌。
CVSS Information
N/A
Vulnerability Type
N/A