Skip to content

fix(fetch): guard against private-IP and cloud metadata SSRF (#4838) - #4890

Open
MustafaKemal0146 wants to merge 1 commit into
modelcontextprotocol:mainfrom
MustafaKemal0146:fix/fetch-ssrf-private-ip-guard
Open

MustafaKemal0146 wants to merge 1 commit into
modelcontextprotocol:mainfrom
MustafaKemal0146:fix/fetch-ssrf-private-ip-guard

Conversation

@MustafaKemal0146

Copy link
Copy Markdown

Summary

Resolves #4838

This PR adds Server-Side Request Forgery (SSRF) protection to mcp-server-fetch:

  • Validates target hostnames in both fetch_url and check_may_autonomously_fetch_url before issuing requests.
  • Guards against loopback (127.0.0.1, ::1, localhost), RFC1918 private IP subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), link-local addresses (169.254.0.0/16, fe80::/10), reserved/multicast/unspecified addresses, and cloud metadata endpoints (169.254.169.254, 100.100.100.100).
  • Validates redirect targets via an httpx request event hook (_validate_request_host) to prevent open redirects from reaching private or metadata endpoints.
  • Allows local development and testing by setting the environment variable FETCH_ALLOW_PRIVATE_IPS to "1" or "true" (case-insensitive).

Rationale

Without this check, an LLM or malicious user-controlled prompt can instruct mcp-server-fetch to query loopback or private services (such as local administrative consoles, Docker daemon APIs, or internal microservices) or fetch cloud instance metadata (AWS, GCP, Azure, Alibaba Cloud) containing temporary IAM credentials and configuration secrets. Validating destination hostnames and redirect targets mitigates these attack vectors.

Test Plan

  • Added unit test suite TestIsPrivateOrRestrictedHost covering loopback, private subnets, cloud metadata IPs, .local domains, public domains, and environment variable override.
  • Added TestSSRFProtectionInFetchUrl testing direct fetch blocks on 127.0.0.1, localhost, RFC1918 IPs, metadata IPs, IPv6 loopback, environment variable bypass, public URL handling, and redirect-to-private/metadata blocking.
  • Added TestSSRFProtectionInRobotsTxt testing robots.txt check on loopback/localhost/metadata and redirect blocking.
  • Verified all 43 tests pass with uv run pytest in src/fetch.
  • Verified type checking with uv run pyright (0 errors) and formatting/lint with uv run ruff check (clean).

Disclosure: Implemented with AI assistance under human review.

Copilot AI balanced review requested due to automatic review settings September 28, 2026 19:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mcp-server-fetch follows redirects with no private-IP / metadata SSRF guard |

2 participants