Skip to content
Common SSRF Vulnerability Discovered in Multiple MCP Implementations

Common SSRF Vulnerability Discovered in Multiple MCP Implementations

First seen 6 Oct 2026, 00:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 02:26 UTC
  • •Five organizations, including Google and JPMorgan, confirmed the same SSRF vulnerability.
  • •The vulnerability is attributed to unsafe handling of upstream data in MCP servers.
  • •CVE-2026-14540 has a high severity rating of 8.0, while CVE-2026-97228 is rated low.

Independent researcher Syed Anas Mohiuddin disclosed a server-side request forgery (SSRF) vulnerability affecting Model Context Protocol (MCP) servers at five organizations, including Google and JPMorgan Chase. The flaw arises from unsafe handling of upstream data and a structural gap in MCP server design. Each organization confirmed and fixed the issue independently, supporting Mohiuddin's hypothesis that the vulnerability is not due to a single implementation error. The vulnerability has been documented under CVE-2026-14540, with a high severity rating of 8.0. A related CVE, CVE-2026-97228, was published later but is rated low severity. The issue remains open in five US federal MCP servers. The findings indicate a broader risk across unrelated systems that utilize the same protocol.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-01
Initial hypothesis proposed
Mohiuddin suggested that the SSRF issue in MCP servers is structural, not accidental, based on one confirmed case.
anas-security-portfolio.vercel.app
2026-07-03
CVE-2026-14540 reserved
The CVE was reserved for the SSRF vulnerability found in Google's MCP Toolbox, credited to Mohiuddin.
Unite.Ai
2026-07-31
CVE-2026-14540 published
The vulnerability in Google’s MCP Toolbox was officially published with a CVSS score of 8.0.
Unite.Ai
2026-09-02
Security issues reported in US federal MCP servers
Mohiuddin filed security issues in five MCP servers for US federal government, which are still in triage.
anas-security-portfolio.vercel.app
2026-09-25
CVE-2026-97228 published
A related but lower severity CVE was published, rated at 2.7.
Unite.Ai

More articles in this cluster (5)

Following this threat?

Track Google and CVE-2026-14540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which organizations are affected?
The affected organizations include Google, JPMorgan Chase, Weaviate, France’s interministerial digital directorate, and the Tangerang City government in Indonesia.
What is the severity of the vulnerabilities?
CVE-2026-14540 has a high severity rating of 8.0, while CVE-2026-97228 is rated low at 2.7.
What should organizations do?
Organizations should review their MCP implementations for the SSRF vulnerability and apply any available patches.