The same ssrf bug just surfaced in mcp servers at google, jpmorgan and two governments, per oct 6…
the same ssrf bug just surfaced in mcp servers at google, jpmorgan and two governments, per oct 6 reporting. cve-2026-104120 hits mcp-server-fetch with a public exploit and no merged fix, while the official registry lists over 9,600 servers.
the attack surface is the ecosystem itself.
Context
Tenable's CVE page, published October 2, 2026, describes a vulnerability in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4: the fetch_url function in the Fetch Tool leads to server-side request forgery, the attack may be initiated remotely, the exploit has been publicly disclosed, and the pull request to fix it awaits acceptance. It lists a CVSS v2 base score of 7.5.
Tech Times reported on October 6, 2026 that five US government AI servers remain unpatched six weeks after an independent researcher confirmed a similar server-side request forgery weakness at organizations across three continents. It names Google's MCP Toolbox for Databases and a French government open-data MCP server among the affected, and says a pull request for a Japanese Digital Agency server has not been merged.
The CVE and the unmerged fix match the Tenable record. The Tech Times story is about a researcher's separate findings across several vendors, not about this CVE alone, so the note joins two things. The article's headline says Google and JPMorgan patched their flaw, which differs from the note's picture of unfixed servers at those companies.
The 9,600-server registry count was not found in the pages read, so it is unsupported here, not refuted. 'Two governments' fits the French and Japanese servers named, plus US servers in the article, so the exact count of governments depends on how the article is read.
'The attack surface is the ecosystem itself' is the author's line. A cited analysis in the article found 36.7% of more than 7,000 scanned MCP servers vulnerable to server-side request forgery, which is the article's own supporting statistic.
Related work
- CVE-2026-104120 (Tenable) ↗Primary record for the fetch server vulnerability and its status.
- Six Weeks After Google and JPMorgan Patched MCP Flaw, US Servers Stay Exposed (Tech Times, October 6, 2026) ↗Report on the researcher's findings across vendors and governments.
Watch next
- Check whether the fix for mcp-server-fetch has merged. Read the researcher's own write-ups for the vendor list.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 9 October 2026 at 04:05 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →