top of page
perceptive_background_267k.jpg

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP In…

Published:

28 April 2026 at 22:00:00

Alert date:

29 April 2026 at 23:01:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A server-side request forgery vulnerability was discovered in Algovate xhs-mcp version 0.8.11. The vulnerability affects the xhs_publish_content function in the MCP Interface component, specifically through manipulation of the media_paths argument. The attack can be initiated remotely and an exploit has been made publicly available. The project maintainers were notified early through an issue report but have not yet responded to address the vulnerability.

Technical details

Mitigation steps:

Affected products:

Algovate xhs-mcp

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page