What is CVE-2026-49856?
In @jshookmcp/jshook version 0.3.1, the central SSRF authorization policy for the network domain fails to properly block private, loopback, link-local, and reserved targets unless an explicit authorization is provided. This vulnerability affects MCP servers that provide AI agents with JavaScript analysis and security research tools. Users are advised to review their network configurations and ensure explicit authorization is enforced.
Azərbaycanca: @jshookmcp/jshook 0.3.1 versiyasında mərkəzi SSRF icazə siyasətinin düzgün tətbiq edilməməsi səbəbindən şəbəkə səviyyəsində qorunan özəl, loopback və reserved hədəflərə icazəsiz giriş mümkündür. Bu boşluq AI agentlərinə JavaScript analizi və təhlükəsizlik tədqiqatı alətləri təqdim edən serverə təsir edir. İstifadəçilərə müvəqqəti olaraq şəbəkə konfiqurasiyalarını nəzərdən keçirərək explicit authorization əlavə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What network targets are affected by the SSRF vulnerability in @jshookmcp/jshook version 0.3.1?
This vulnerability allows unauthorized access to private, loopback, link-local, and reserved network targets.
What is recommended to mitigate CVE-2026-49856?
Users are advised to review their network configurations and ensure explicit authorization is enforced.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.