CVE-2026-81091 | mcp-use up to 2.3.2 Proxy Middleware mcp-proxy.ts mountMcpProxy __mcp_target server-side request forgery

SecurityVulns

A vulnerability marked as problematic has been reported in mcp-use up to 2.3.2. This impacts the function mountMcpProxy of the file libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts of the component Proxy Middleware. This manipulation of the argument __mcp_target causes server-side request forgery.

This vulnerability is registered as CVE-2026-81091. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More