Known Vulnerabilities for Fetcher-mcp by Jae-jae
Listed below are 10 of the newest known vulnerabilities associated with "Fetcher-mcp" by "Jae-jae".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82476 json | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetche... | Not Provided | 2026-08-29 | 2026-08-31 |
| CVE-2026-78385 json | RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are con... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-74858 json | A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file ... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-69078 json | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionalit... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-63744 json | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects w... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-63736 json | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL h... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-57349 json | Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-55524 json | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-51152 json | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-50190 json | Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/contro... | Not Provided | 2026-08-20 | 2026-08-20 |