CVE-2026-85666 | OGX-AI OGX up to 1.3.1 MCP Tool Definitions /v1/responses validate_url_not_private server_url server-side request forgery
A vulnerability was found in OGX-AI OGX up to 1.3.1. It has been declared as critical. Affected by this vulnerability is the function validate_url_not_private of the file /v1/responses of the component MCP Tool Definitions. The manipulation of the argument server_url results in server-side request forgery.
This vulnerability was named CVE-2026-85666. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More