8.5
HIGH CVSS 3.1
CVE-2026-59973
FrontMCP Server-Side Request Forgery Security Fix Bypass
Description

## Summary The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is reached through hostname resolution, redirects, or IPv4-mapped IPv6 syntax. FrontMCP latest release v1.2.1 and current main still call `OpenAPIToolGenerator.fromURL()` and `OpenAPIToolGenerator.fromJSON()` from `mcp-from-openapi` 2.3.0 when loading OpenAPI adapters. An attacker who can cause a hosted or multi-user FrontMCP deployment to load an untrusted OpenAPI spec can trigger requests from the server to localhost or private services during tool generation. This is a latest-version bypass of the previous fix. A direct `http://127.0.0.1` `$ref` control is now denied and produces zero canary hits, while semantically equivalent loopback targets still reach the canary. ## Latest versions checked - `frontmcp` npm latest: 1.2.1 - `@frontmcp/adapters` npm latest: 1.2.1 - `mcp-from-openapi` npm latest: 2.3.0 - FrontMCP release tag: v1.2.1, commit db323976c66297d684a3e63bbfe1db6b310f2944 - FrontMCP current main checked: c15b79abe8c6a3cb71d4b7a3bafb8190730dc756 The release tag and current main both keep `mcp-from-openapi` 2.3.0 in `package.json` and `libs/adapters/package.json`, and both keep the OpenAPI adapter forwarding untrusted `url`, `spec`, and `loadOptions.refResolution` into `OpenAPIToolGenerator`. ## Technical details FrontMCP's OpenAPI adapter reaches the affected dependency paths: - `libs/adapters/src/openapi/openapi.adapter.ts` imports `OpenAPIToolGenerator` from `mcp-from-openapi`. - `loadOpenAPISpec()` calls `OpenAPIToolGenerator.fromURL(this.options.url, ...)` and forwards `loadOptions.refResolution`. - The same method calls `OpenAPIToolGenerator.fromJSON(this.options.spec, ...)` and forwards `loadOptions.refResolution`. In `mcp-from-openapi` 2.3.0, the patched guard is applied before the HTTP resolver fetches an external `$ref`. It checks the parsed URL hostname string against deny patterns for direct local and private addresses. The resolver does not resolve hostnames before allow or deny decisions, does not pin the validated IP to the fetch, and does not revalidate redirect targets before following them. It also misses IPv4-mapped IPv6 loopback forms. As a result, these URLs are accepted by the guard but cause a loopback request from the backend: - `http://127.0.0.1.nip.io:<port>/schema.json`, because the hostname string is not a direct IP even though it resolves to 127.0.0.1. - `http://127.0.0.1.nip.io:<port>/redirect`, because the first host passes and the actual request follows a redirect to `http://127.0.0.1:<port>/schema.json`. - `http://[::ffff:127.0.0.1]:<port>/schema.json` and `http://[::ffff:7f00:1]:<port>/schema.json`, because IPv4-mapped IPv6 loopback is not normalized and denied. `OpenAPIToolGenerator.fromURL()` is also still unguarded for the initial OpenAPI spec URL. The PoC includes that as supporting evidence, but the primary report is the external `$ref` fix bypass. ## Reproduction The attached local PoC starts a loopback canary and loads generated OpenAPI specs using `mcp-from-openapi` 2.3.0. The request body schema contains a single external `$ref` for each test case. The canary records every backend-origin request. Run: ```bash cd /home/unkn0wn/security_audit/frontmcp-ssrf-poc node repro-frontmcp-latest-ssrf-bypasses.mjs ``` Important output from a fresh run on 2026-05-25: ```json {"name":"direct-127-denied-control","kind":"external_ref","refUrl":"http://127.0.0.1:45117/schema.json","ok":false,"hitCount":0,"hits":[]} {"name":"dns-name-to-127-bypass","kind":"external_ref","refUrl":"http://127.0.0.1.nip.io:45117/schema.json","ok":true,"hitCount":1,"hits":[{"url":"/schema.json","host":"127.0.0.1.nip.io:45117","authorization":null}]} {"name":"dns-name-to-127-bypass-with-allowedHosts","kind":"external_ref","refUrl":"http://127.0.0.1.nip.io:45117/schema.json","ok":true,"hitCount":1,"hits":[{"url":"/schema.json","host":"127.0.0.1.nip.io:45117","authorization":null}]} {"name":"redirect-to-127-after-allowed-host","kind":"external_ref","refUrl":"http://127.0.0.1.nip.io:45117/redirect","ok":true,"hitCount":2,"hits":[{"url":"/redirect","host":"127.0.0.1.nip.io:45117","authorization":null},{"url":"/schema.json","host":"127.0.0.1:45117","authorization":null}]} {"name":"ipv4-mapped-ipv6-dotted-bypass","kind":"external_ref","refUrl":"http://[::ffff:127.0.0.1]:45117/schema.json","ok":true,"hitCount":1,"hits":[{"url":"/schema.json","host":"[::ffff:7f00:1]:45117","authorization":null}]} {"name":"ipv4-mapped-ipv6-hex-bypass","kind":"external_ref","refUrl":"http://[::ffff:7f00:1]:45117/schema.json","ok":true,"hitCount":1,"hits":[{"url":"/schema.json","host":"[::ffff:7f00:1]:45117","authorization":null}]} {"name":"external-refs-disabled-control","kind":"external_ref","refUrl":"http://127.0.0.1.nip.io:45117/schema.json","ok":true,"hitCount":0,"hits":[]} ``` Controls: 1. Direct loopback `$ref` is denied and the canary records zero requests. 2. Numeric IPv4 variants tested as parser controls were denied with zero requests. 3. Default `file://` resolution was denied in this runtime. 4. Setting `refResolution.allowedProtocols: []` prevents the external request, but this is not the default. ## Impact The previous advisory documented SSRF during untrusted OpenAPI `$ref` dereferencing. The latest patched version still lets an attacker trigger backend-origin requests to loopback or private network services through equivalent URL forms. In hosted or multi-user FrontMCP deployments where users can import or configure OpenAPI specs, this can expose internal admin APIs, metadata-like services, and other network endpoints that external users cannot reach directly. The impact depends on whether a deployment treats OpenAPI adapter configuration as trusted administrator-only input. If untrusted authenticated users can import specs, this is a high-impact SSRF fix bypass. If only a local administrator can configure OpenAPI specs, the practical severity is lower. ## Remediation 1. Do not rely on parsed hostname denylist checks for external `$ref` URLs. 2. Resolve hostnames before the request and reject loopback, private, link-local, multicast, unspecified, and metadata ranges. 3. Normalize IPv4-mapped IPv6 before range checks. 4. Revalidate every redirect target before following it, or disable redirects during external `$ref` dereferencing. 5. Pin the validated IP to the actual request with a custom dispatcher, lookup hook, or equivalent connect-time control. 6. Apply the same protected client to `fromURL()` initial spec loads. 7. Consider disabling external refs by default for untrusted OpenAPI specs and requiring explicit allowlists. 8. Add regression tests for direct loopback, DNS-to-loopback, redirect-to-loopback, IPv4-mapped IPv6, numeric IP forms, file refs, and disabled external refs.

INFO

Published Date :

Sept. 11, 2026, 10:02 p.m.

Last Modified :

Sept. 11, 2026, 10:02 p.m.

Remotely Exploit :

Yes !

Source :

github-security-advisories
Affected Products

The following products are affected by CVE-2026-59973 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH github
Solution
Update the mcp-from-openapi dependency to resolve SSRF vulnerabilities and prevent unauthorized server-side requests.
  • Update mcp-from-openapi to a version with a robust SSRF fix.
  • Ensure OpenAPI specs are from trusted sources.
  • Disable external `$ref` dereferencing if not needed.
  • Implement strict hostname validation for all requests.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-59973.

URL Resource
https://github.com/agentfront/frontmcp/security/advisories/GHSA-65h7-9wrw-629c
https://github.com/advisories/GHSA-65h7-9wrw-629c
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-59973 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-59973 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-59973 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.