A vulnerability was found in jae-jae fetcher-mcp up to 0.3.9 and classified as critical. Impacted is the function
fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-74858. It is possible to launch the attack remotely. No exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.