工具在仅校验了 URL 的语法之后,便抓取了调用者提供的 URL。位于 中的处理程序使用 中的 对 参数进行了验证,该函数仅确认字符串以 或 协议开头,并且可以被解析为一个 URL,但并未检查其主机名或该 URL 解析到的实际地址。因此,回环地址、链路本地地址以及私有地址范围均能通过校验,其中包括云服务商用于提供实例元数据的地址(如 )。由于该 URL 未做进一步检查就被传递给 web-browser 执行器,抓取到的文档内容会直接返回在工具响应中,这意味着 MCP 服务器的任何调用方都可以让服务器请求仅主机端可达
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apify | actors-mcp-server | < 0.9.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apify | actors-mcp-server | 0 ~ 0.9.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet