Vibe Coding
CVE-2026-86122: Rowboat lets any authenticated user aim an MCP server URL at cloud metadata
NVD published CVE-2026-86122 on 2026-09-05: Rowboat through 0.9.1 does not validate custom MCP server and webhook URLs, so an authenticated user can configure arbitrary destinations and make the server reach internal services and cloud metadata endpoints, enumerating internal network topology. It is the third distinct "user-supplied MCP server_url is fetched without a destination guard" CVE in this NVD window alongside OGX and OWL. Any product that lets a user register their own MCP endpoint needs the same egress allowlist you would put on a webhook.
Source
↳ Follow the thread