HIGH 8.5 GitHub
CVE-2026-59973
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
## Summary
The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is reached through hostname resolution, redirects, or IPv4-mapped IPv6 syntax.
FrontMCP latest release v1.2.1 and current main still call `OpenAPIToolGenerator.fromURL()` and `OpenAPIToolGenerator.fromJSON()` from `mcp-from-opena
Affected Products
- npm/mcp-from-openapi >= 2.3.0, < 2.5.0
- npm/@frontmcp/adapters >= 1.2.1, < 1.5.0
- npm/frontmcp >= 1.2.1, < 1.5.0
References
- https://github.com/advisories/GHSA-65h7-9wrw-629c
- https://github.com/agentfront/frontmcp/security/advisories/GHSA-65h7-9wrw-629c
- https://github.com/advisories/GHSA-65h7-9wrw-629c
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-09-11 via GitHub. Affected: npm/mcp-from-openapi >= 2.3.0, < 2.5.0, npm/@frontmcp/adapters >= 1.2.1, < 1.5.0, npm/frontmcp >= 1.2.1, < 1.5.0.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.