CVE-2026-81093 | Apify Actors MCP Server up to 0.9.11 Get HTML Skeleton Tool src/utils/generic.ts isValidHttpUrl url server-side request forgery

SecurityVulns

A vulnerability classified as problematic has been found in Apify Actors MCP Server up to 0.9.11. Affected by this vulnerability is the function isValidHttpUrl of the file src/utils/generic.ts of the component Get HTML Skeleton Tool. Performing a manipulation of the argument url results in server-side request forgery.

This vulnerability is reported as CVE-2026-81093. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More