CVE-2026-7094 Details
Description
A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
A server-side request forgery (SSRF) vulnerability has been identified in ShadowCloneLabs GlutamateMCPServers versions prior to commit e2de73280b01e5d943593dd1aa2c01c5b9112f78. The vulnerability exists in the puppeteer_navigate component, specifically within the file src/puppeteer/index.ts. The issue arises because the puppeteer_navigate tool accepts a user-supplied URL argument and passes it directly to the page.goto function without proper validation or allowlisting. This flaw allows an attacker with network access to the MCP/HTTP interface to manipulate the URL and have the headless browser navigate to arbitrary destinations. Such exploitation could access internal services, cloud metadata endpoints, or other restricted resources, potentially leading to unauthorized information disclosure and further compromise, depending on the environment.
No specific remediation is known at this time, but it is recommended to update to a version that includes the patch for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/BruceJqs/public_exp/issues/7 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://github.com/ShadowCloneLabs/GlutamateMCPServers/ | [email protected] | Product |
| https://github.com/ShadowCloneLabs/GlutamateMCPServers/issues/8 | [email protected] | Issue Tracking |
| https://vuldb.com/submit/800725 | [email protected] | Third Party Advisory |
| https://vuldb.com/vuln/359669 | [email protected] | Third Party Advisory |
| https://vuldb.com/vuln/359669/cti | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shadowclonelabs glutamate mcp servers | <= 2025-06-26 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 27, 2026 | New CVE Received | [email protected] |