CVE-2026-7729 Details
Description
A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
A server-side request forgery (SSRF) vulnerability has been identified in pixelsock directus-mcp version 1.0.0. The issue arises in the MCP Interface component, specifically within the validateUrl function of index.ts. The vulnerability allows an attacker to manipulate the fileUrl argument, leading to unauthorized outbound HTTP requests from the server to internal or external destinations. This could result in information disclosure or further exploitation. The vulnerability can be exploited remotely, and a proof-of-concept has been made public. A pull request to address this issue is pending acceptance.
A pull request to patch this vulnerability and upgrade affected dependencies is available but not yet merged.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/BruceJqs/public_exp/issues/36 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://github.com/pixelsock/directus-mcp/ | [email protected] | Source CodeVendor |
| https://github.com/pixelsock/directus-mcp/issues/13 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/pixelsock/directus-mcp/pull/14 | [email protected] | Source CodeVendor |
| https://vuldb.com/submit/807539 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360904 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360904/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pixelsock directus-mcp | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |
Volerion