CVE-2026-59973 | FrontMCP 1.2.1 OpenAPI Adapter openapi.adapter.ts OpenAPIToolGenerator.fromURL url server-side request forgery
A vulnerability, which was classified as critical, was found in FrontMCP 1.2.1. This affects the function OpenAPIToolGenerator.fromURL of the file libs/adapters/src/openapi/openapi.adapter.ts of the component OpenAPI Adapter. The manipulation of the argument url results in server-side request forgery.
This vulnerability is known as CVE-2026-59973. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More