


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the comp…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 05:01:43
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
A server-side request forgery (SSRF) vulnerability was discovered in TencentCloudBase CloudBase-MCP up to version 2.17.0. The vulnerability affects the openUrl function in the open-url API endpoint, where manipulation of the req.body.url parameter leads to SSRF attacks. The vulnerability can be exploited remotely and public exploits are available. The issue is resolved in version 2.17.1 with patch 3f678a1e7bd400cd76469d61024097d4920dc6b5. Users are strongly recommended to upgrade to the patched version immediately.
Technical details
Mitigation steps:
Affected products:
TencentCloudBase CloudBase-MCP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7221
https://github.com/TencentCloudBase/CloudBase-MCP/
https://github.com/TencentCloudBase/CloudBase-MCP/commit/3f678a1e7bd400cd76469d61024097d4920dc6b5
https://github.com/TencentCloudBase/CloudBase-MCP/issues/509
https://github.com/TencentCloudBase/CloudBase-MCP/pull/510
https://github.com/TencentCloudBase/CloudBase-MCP/releases/tag/v2.17.1
https://vuldb.com/submit/802230
https://vuldb.com/vuln/359821
https://vuldb.com/vuln/359821/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
