<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:21:46.728523+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338468</id>
    <title>EUVD-2026-338468</title>
    <updated>2026-10-06T08:21:46.787630+00:00</updated>
    <content>EUVD-2026-338468</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46341</id>
    <title>fkie_cve-2026-46341</title>
    <updated>2026-10-06T08:21:46.787686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation domains with String.startsWith() rather than URL hostname comparison, allowing attacker-controlled URLs such as `https://docs.apify.com.evil.com/` and `https://docs.apify.com@evil.com/` to pass the ALLOWED_DOC_DOMAINS check and return arbitrary fetched content to the LLM. This issue is fixed in version 0.9.21.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jwp7-wg77-3w9v</id>
    <title>GHSA-jwp7-wg77-3w9v — Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching</title>
    <updated>2026-10-06T08:21:46.787740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @apify/actors-mcp-server</p>
<p>### Summary
The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subdomains (e.g., `https://docs.apify.com.evil.com/`), enabling the tool to fetch and return arbitrary web content to the LLM.</p>
<p>### Details
#### Vulnerable component</p>
<p>`src/tools/common/fetch_apify_docs.ts`, line 51:</p>
<p>```typescript
const isAllowedDomain = ALLOWED_DOC_DOMAINS.some((domain) =&gt; url.startsWith(domain));
```</p>
<p>`src/const.ts`, lines 167-170:</p>
<p>```typescript
export const ALLOWED_DOC_DOMAINS = [
    'https://docs.apify.com',
    'https://crawlee.dev',
] as const;
```</p>
<p>#### How the bypass works</p>
<p>`String.startsWith('https://docs.apify.com')` matches any string beginning with that prefix, including:</p>
<p>- `https://docs.apify.com.evil.com/payload` - attacker-controlled subdomain
- `https://docs.apify.com@evil.com/payload` - userinfo component in URL (browser behavior varies, but `fetch()` in Node.js may follow this)
- `https://docs.apify.com.evil.com:8080/path` - custom port on attacker domain</p>
<p>All of these pass the `startsWith` check because they begin with the exact string `https://docs.apify.com`.</p>
<p>#### The fetched content is returned to the LLM</p>
<p>After the allowlist check passes, the tool fetches the URL and returns the full page content as markdown (`fetch_apify_docs.ts:69-103`):</p>
<p>```typescript
const response = await fetch(url);
// ...
const html = await response.text();
markdown…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jwp7-wg77-3w9v"/>
  </entry>
</feed>
