


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown fun…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 19:18:12
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A server-side request forgery (SSRF) vulnerability has been identified in ShadowCloneLabs GlutamateMCPServers. The vulnerability affects the puppeteer_navigate component, specifically the src/puppeteer/index.ts file. Attackers can exploit this by manipulating the url argument to perform SSRF attacks remotely. The exploit has been publicly disclosed and is available for use. The project uses a rolling release system, making version tracking difficult. Despite early notification through issue reports, the project maintainers have not yet responded to address the vulnerability.
Technical details
Mitigation steps:
Affected products:
ShadowCloneLabs GlutamateMCPServers
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7094
https://github.com/BruceJqs/public_exp/issues/7
https://github.com/ShadowCloneLabs/GlutamateMCPServers/
https://github.com/ShadowCloneLabs/GlutamateMCPServers/issues/8
https://vuldb.com/submit/800725
https://vuldb.com/vuln/359669
https://vuldb.com/vuln/359669/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
