Researcher finds SSRF flaws in MCP servers from Google, Anthropic, Microsoft and Weaviate
Over nine months in 2026 a researcher found the same SSRF bug shape in MCP servers shipped by Google, Anthropic, Microsoft and Weaviate. Google assigned CVE-2026-14540 (CVSS 8.0) and fixed it in mcp-toolbox v1.5.0; the other vendors have not confirmed fixes.
- Google: CVE-2026-14540, CVSS 8.0, fixed in mcp-toolbox v1.5.0
- Anthropic and Microsoft: URL guard exists but get_prompt bypasses it
- Weaviate: apiEndpoint field dodged two rounds of baseURL hardening
- Flaw lets attackers redirect requests to internal IPs and metadata endpoints
Read next
Security