← Terug naar overzicht

A server-side request forgery (SSRF) vulnerability has been identified in ddfourtwo sentry-selfhosted-mcp version 0.4.0. The flaw exists in an unknown function of the raw_sentry_api component, where manipulation of the endpoint argument allows SSRF attacks. The vulnerability can be exploited remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The project maintainer was notified via an issue report but has not yet responded or issued a patch. The lack of vendor response and public exploit availability makes this a significant risk for users of the affected software.

Affected products

  • ddfourtwo sentry-selfhosted-mcp 0.4.0

Related CVE's

  • CVE-2026-81421

Categories

  • Security Tools
  • Web Technologies
  • Zero-Day Vulnerabilities