CVE-2026-39885 | agentfront frontmcp/adapters/sdk/mcp-from-openapi Model Context Protocol initialize ref server-side request forgery (GHSA-v6ph-xcq9-qxxj)
A vulnerability classified as critical was found in agentfront frontmcp, adapters, sdk and mcp-from-openapi. This affects the function initialize of the component Model Context Protocol. The manipulation of the argument ref results in server-side request forgery.
This vulnerability is identified as CVE-2026-39885. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.