在 cyberchitta scrapling-fetch-mcp 0.2.2 及更早版本中被发现存在一个漏洞。受影响的组件是文件 中的 / 函数。攻击者通过执行特定的操作,可引发服务端请求伪造(SSRF)漏洞,且该攻击可远程发起。升级到 0.2.3 版本即可修复此问题,对应的修复补丁编号为 。建议升级受影响组件以消除风险。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyberchitta | scrapling-fetch-mcp | 0.2.0 |
affected |
0.2.1 |
affected | ||
0.2.2 |
affected | ||
0.2.3 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyberchitta | scrapling-fetch-mcp | 0.2.0 |
cpe:2.3:a:cyberchitta:scrapling-fetch-mcp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet