Skip to main content

CVE-2026-53957: CWE-918: Server-Side Request Forgery (SSRF) in contentful contentful-mcp-server

0
High
VulnerabilityCVE-2026-53957cvecve-2026-53957cwe-918
Published: 09/15/2026 (09/15/2026, 14:34:53 UTC)
Source: CVE Database V5
Vendor/Project: contentful
Product: contentful-mcp-server

Description

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network options to LLM-controlled tool arguments and combine those options with the server's CONTENTFUL_MANAGEMENT_TOKEN. After space_to_space_migration_handler enables the migration tools, a direct MCP call or prompt injection through attacker-controlled Contentful content can redirect Contentful Management API requests and their Authorization header to an attacker-controlled host or proxy. The regular tools that use createToolClient are unaffected because those tools pin the host from server configuration. Exposure of the personal access token permits persistent out-of-band access to every Contentful space within the token's scope. This issue is fixed in @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5.

CVSS v3.1

Score 7.7high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected software

contentful

contentful-mcp-server

Affected versions
<1.7.19

@contentful

mcp-server

Affected versions
<1.7.19

@contentful

mcp-tools

Affected versions
<0.4.5
GitHub Actionsmore threats →ai
contentful/contentful-mcp-server
pkg:github/contentful/contentful-mcp-server
Affected versions
<1.7.19
GitHub Actionsmore threats →ai
contentful/mcp-tools
pkg:github/contentful/mcp-tools
Affected versions
<0.4.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 15:01:37 UTC

Technical Analysis

Contentful MCP Server versions before 1.7.19 and MCP Tools before 0.4.5 contain a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in the space-to-space migration tools. The vulnerability occurs because the export_space and import_space functions expose network options (host, proxy, rawProxy, insecure) to arguments controlled by large language models (LLMs) or attacker input. These options are combined with the server's CONTENTFUL_MANAGEMENT_TOKEN, enabling an attacker to redirect Contentful Management API requests, including the Authorization header, to attacker-controlled hosts or proxies. This can lead to persistent out-of-band access to all Contentful spaces accessible by the token. Tools that use createToolClient are not affected as they pin the host from server configuration. The vulnerability is addressed by updates to @contentful/mcp-server (1.7.19) and @contentful/mcp-tools (0.4.5).

Potential Impact

An attacker can exploit this SSRF vulnerability to redirect authorized API requests to attacker-controlled hosts, exposing the CONTENTFUL_MANAGEMENT_TOKEN. This token exposure allows persistent unauthorized access to all Contentful spaces within the token's scope. The vulnerability does not affect availability or integrity but has a high confidentiality impact. There are no known exploits in the wild as of the published date.

Mitigation Recommendations

Upgrade to @contentful/mcp-server version 1.7.19 or later and @contentful/mcp-tools version 0.4.5 or later to remediate this vulnerability. These versions fix the SSRF issue by restricting exposure of network options and securing the management token. No other mitigations are specified or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-11T15:50:01.282Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa95a7655bf5e2cf5f52f63

Added to database: 09/15/2026, 14:47:18 UTC

Last enriched: 09/15/2026, 15:01:37 UTC

Last updated: 09/16/2026, 02:09:03 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses