


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP In…
Published:
28 april 2026 om 22:00:00
Alert date:
29 april 2026 om 23:01:57
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A server-side request forgery vulnerability was discovered in Algovate xhs-mcp version 0.8.11. The vulnerability affects the xhs_publish_content function in the MCP Interface component, specifically through manipulation of the media_paths argument. The attack can be initiated remotely and an exploit has been made publicly available. The project maintainers were notified early through an issue report but have not yet responded to address the vulnerability.
Technical details
Mitigation steps:
Affected products:
Algovate xhs-mcp
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7417
https://github.com/Algovate/xhs-mcp/
https://github.com/Algovate/xhs-mcp/issues/6
https://github.com/BruceJqs/public_exp/issues/21
https://vuldb.com/submit/803991
https://vuldb.com/vuln/360154
https://vuldb.com/vuln/360154/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
