๐Ÿ” CVE Alert

CVE-2026-49856

MEDIUM 4.3

@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorization object allows private network access. The policy is enforced by raw HTTP/TCP/TLS RTT tools, but the ICMP probe and traceroute tools resolve the target and invoke the native ICMP/traceroute sink directly. An MCP client with access to an active network domain can therefore ask the jshookmcp server to probe internal addresses even when local SSRF access is disabled for the other raw network tools. This exposes an internal reachability and route mapping primitive from the server network position. Version 0.3.2 fixes the issue.

CWE CWE-918
Vendor vmoranv
Product jshookmcp
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for vmoranv jshookmcp

Be the first to know when new medium vulnerabilities affecting vmoranv jshookmcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

vmoranv / jshookmcp
= 0.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vmoranv/jshookmcp/security/advisories/GHSA-c5r6-m4mr-8q5j github.com: https://github.com/vmoranv/jshookmcp/commit/02111311f7bd0f86a7d7ef8538986594b3a18afa