springdoc-openapi-starter-common-mcp is vulnerable to Server-Side Request Forgery (SSRF)
82
High Risk
The MCP tool callback builds outbound request paths by substituting tool-supplied path parameters directly into the URL without encoding. Injecting /, ?, #, or .. into a parameter retargets the request to unintended routes, including endpoints excluded from the API or marked @McpIgnore, and can smuggle query strings that expose caller headers. This lets a caller reach sensitive application endpoints through the MCP tool surface. The patch percent-encodes path segments before building the request.
You are affected if you are using a version that falls within the vulnerable range and you have the springdoc MCP starter on the classpath, which registered MCP tool callbacks by default in the affected range.
springdoc-openapi-starter-common-mcp is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.0.3 - 3.1.0.
Upgrade the org.springdoc:springdoc-openapi-starter-common-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.