CVE-2026-81093
Last modified
CVE-2026-81093 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed the string began with an http or https scheme and parsed as a URL and inspected neither the host name nor the address it resolves to.
Description
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed the string began with an http or https scheme and parsed as a URL and inspected neither the host name nor the address it resolves to. Loopback, link-local and private ranges therefore passed, including the address cloud providers use to serve instance metadata. The unchecked URL was handed to the web-browser actor and the fetched document was returned in the tool response, so any caller of the MCP server could make it request an endpoint reachable only from the host and read the result, including instance credentials. Version 0.9.12 removes the tool.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| apify | actors-mcp-server | < 0.9.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81093?
How severe is CVE-2026-81093?
How do I fix CVE-2026-81093?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8106A reflected HTML injection vulnerability was identified in t…6.1
- CVE-2026-8108The installation of Fuji Tellus adds a driver to the kernel …7.8
- CVE-2026-8109An exposed dangerous method on the Core Server of Ivanti End…6.5
- CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perfo…7.2
- CVE-2026-81091The proxy middleware in mcp-use's inspector forwards request…8.6
- CVE-2026-81092mcp-go accepted requests on its HTTP transports without chec…6.8
- CVE-2026-81094The mcp-router CLI served its MCP aggregator on every interf…9.1
- CVE-2026-81095pg-aiguide started its MCP HTTP transport without enabling t…6.8
- CVE-2026-81096ToolUniverse ran caller-supplied Python inside a sandbox tha…10
- CVE-2026-81097The execute_ruby tool is documented as a read-only Ruby sand…8.4
- CVE-2026-81098The Telnyx MCP server exposed its HTTP transport on every in…9.1
- CVE-2026-81099tiger-slack started its MCP HTTP transport without enabling …6.8
Are you affected by CVE-2026-81093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
