{"data":{"id":"2566e51c-0e92-4388-b0e4-405256c664de","title":"CVE-2026-49856: @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version ","summary":"In @jshookmcp/jshook version 0.3.1, an MCP server (a tool that gives AI agents JavaScript analysis capabilities) has a security gap where ICMP probe and traceroute tools bypass SSRF protections (security rules that block access to private internal networks). This allows an attacker with access to the server to map internal networks and probe private addresses that should be blocked.","solution":"Version 0.3.2 fixes the issue.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49856","publishedAt":"2026-08-13T15:19:41.563Z","cveId":"CVE-2026-49856","cweIds":["CWE-918"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["jshookmcp","@jshookmcp/jshook"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T15:19:41.563Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}