CVE-2026-86122 Details
Description
Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.
A server-side request forgery (SSRF) vulnerability has been identified in Rowboat versions through 0.9.1. The issue arises because the application fails to properly validate custom Model Context Protocol (MCP) server and webhook URLs configured by users. This lack of validation allows authenticated users to direct these URLs to internal services or cloud metadata endpoints, potentially leading to unauthorized access or manipulation of data. The vulnerability is exacerbated by the fact that any registered user can create a project and configure these URLs, turning the Rowboat server into a probe for internal network services.
Users are advised to update to Rowboat versions after 0.9.1, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 5, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rowboat | <= 0.9.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2026 | New CVE Received | [email protected] |
Volerion