Bug 2533309 (CVE-2026-85666)
| Summary: | CVE-2026-85666 ogx: OGX: Information disclosure via Server-Side Request Forgery in MCP tool server_url | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | ebourniv, hasun, nyancey, ptisnovs, sbunciak |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OGX, an OpenAI-compatible server. A remote, unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by manipulating the `server_url` parameter within MCP tool definitions. This allows the attacker to force the server to connect to arbitrary internal network addresses, potentially disclosing sensitive information such as cloud metadata or internal credentials.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-14 19:42:40 UTC
|