In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade meta-ads-mcp to version 1.0.115 or higher.
meta-ads-mcp is a Model Context Protocol (MCP) server for Meta Ads - Use Remote MCP at pipeboard.co for easiest setup
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the upload_ad_image process. An attacker can cause the server to make arbitrary outbound HTTP requests to internal or external endpoints by supplying a crafted image_url parameter. This is only exploitable if the server is deployed with the streamable-http transport mode and the attacker can send requests to the MCP HTTP endpoint with any non-empty Bearer token.