THREAT OPS › Threat News › [NVD] CVE-2026-49856 (MEDIUM 4.3) — @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorizatio
[NVD] CVE-2026-49856 (MEDIUM 4.3) — @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorizatio
CVE-2026-49856 CVSS: 4.3 MEDIUM Published: 2026-08-13T15:19:41.563
@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorization object allows private network access. The policy i
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-49856cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49856