<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:26:57.541942+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355198</id>
    <title>EUVD-2026-355198</title>
    <updated>2026-10-06T21:26:57.611192+00:00</updated>
    <content>EUVD-2026-355198</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50143</id>
    <title>fkie_cve-2026-50143</title>
    <updated>2026-10-06T21:26:57.611260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor publisher to use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp tool-loading paths pass this URL to transports in src/mcp/client.ts that attach the victim Authorization bearer token, exposing the Apify API token and enabling access to Actors, stored data, and billable compute. A victim must invoke or inspect the attacker-controlled Actor. This issue is fixed in version 0.10.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6gr2-qh89-hxwm</id>
    <title>GHSA-6gr2-qh89-hxwm — Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token</title>
    <updated>2026-10-06T21:26:57.611313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @apify/actors-mcp-server</p>
<p>## Actor MCP path authority injection leaks Apify token</p>
<p>### Summary</p>
<p>`@apify/actors-mcp-server` version `0.10.7` builds Actor standby URLs by directly concatenating a trusted base URL with an attacker-controlled `webServerMcpPath` value taken from an Actor definition returned by the Apify API. An attacker who publishes a malicious Actor with a crafted `webServerMcpPath` (e.g., `@attacker.example/mcp`) can cause the MCP client to resolve the final URL to an entirely different host. Because the MCP client unconditionally attaches the victim's `Authorization: Bearer &lt;APIFY_TOKEN&gt;` header to every outbound connection, the victim's Apify API token is exfiltrated to the attacker's server. CVSS Base Score: **8.1 (High)**.</p>
<p>### Details</p>
<p>`getActorMCPServerURL()` in `src/mcp/actors.ts:44` constructs the Actor standby MCP URL by naive string concatenation:</p>
<p>```ts
// src/mcp/actors.ts:44
return `${standbyUrl}${mcpServerPath}`;
```</p>
<p>`mcpServerPath` originates from the `webServerMcpPath` field of an Actor definition fetched from the Apify API (`src/utils/actor.ts:24-28`). The field is trimmed and comma-split in `getActorMCPServerPath()` (`src/mcp/actors.ts:14-20`) but is never validated to:</p>
<p>- begin with a `/` (relative path),
- avoid an `@` character (userinfo/authority injection), or
- resolve to the same origin as `standbyUrl`.</p>
<p>When `webServerMcpPath` is set to `@attacker.example/mcp`, the concatenated result becomes:</p>
<p>```
https://real-actor-id.apify.actor@attacker.example/mcp
```</p>
<p>N…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6gr2-qh89-hxwm"/>
  </entry>
</feed>
