CVE-2026-7221 | TencentCloudBase CloudBase-MCP up to 2.17.0 open-url API Endpoint interactive-server.ts openUrl req.body.url server-side request forgery (Issue 509)
A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. It has been declared as critical. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery.
This vulnerability is known as CVE-2026-7221. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is recommended to upgrade the affected component.