# sonatype-2026-005085

@frontmcp/adapters - Server-Side Request Forgery (SSRF)

Published Jul 25, 2026

[Advisory · GHSA-8q49-2h5h-434x](https://github.com/advisories/GHSA-8q49-2h5h-434x)

## Security Details

### Components Impacted

Sonatype Research

### sonatype-2026-005085 Security Details

- **CVE ID**: sonatype-2026-005085  
- **CWE**: N/A  
- **CVE Description**: @frontmcp/adapters - Server-Side Request Forgery (SSRF)  
- **Published**: Jul 25, 2026  
- **CVSS Score & Severity**: 5.9 Medium  
- **CVSS Vector**: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N  
- **EPSS Score**: 0%  
- **Malware**: malware  
- **KEV Status**: Not in KEV Catalog: No known exploits  
- **Affected Ecosystems**: affected  
- **Source**: Sonatype

### References

[GitHub · Advisory · GHSA-8q49-2h5h-434x](https://github.com/advisories/GHSA-8q49-2h5h-434x "https://github.com/advisories/GHSA-8q49-2h5h-434x") THIRD_PARTY
