CVE Tools

Otto Support - SSRF and Token Passthrough with MCP

Bishop FoxBy Derek Rush6 min read

Researchmcp-atlassianMarkItDown
Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR

Server-side request forgery (SSRF) and token passthrough are old web vulnerabilities in new packaging. In an MCP server, a single mishandled URL can turn into RCE on a developer's laptop or a foothold inside a cloud account. This post walks three recent case studies for an mcp-atlassian CVE chain, Microsoft's MarkItDown SSRF, and the marketplace-plugin flaw in OpenClaw. As a closer, mitigations to defuse the risks documented in the case studies are discussed, including destination validation, network segmentation, and, for token passthrough, mostly just not doing it.…

Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store