VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-86122

CVE-2026-86122: Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure ar

Published Sep 5, 2026 CVSS 5.3

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.