Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-65513
CVE-2025-65513
fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.
Published Dec 10, 2025
https://github.com/advisories/GHSA-8fxj-2g9q-8fjw
CVSS Score
High
7.5
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
mcp-fetch-server
1.0.0
npm
mcp-fetch-server
1.0.1
npm
mcp-fetch-server
1.0.2
1-3 of 3
CVE-2025-65513 | Components Impacted | Sonatype Guide | Sonatype Guide