Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-27826] Otto Support - SSRF and Token Passthrough with MCP

Summary

SSRF and token passthrough in MCP servers: the mcp-atlassian SSRF-to-RCE chain (CVE-2026-27826), MarkItDown's SSRF, and an OpenClaw marketplace plugin flaw show why destination validation matters.
Published
Collected

original ↗

Related coverage

back