Vulnerability Description
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.
Related Weaknesses (CWE)
References
- https://github.com/activepieces/activepieces/commit/d385079cf4a9f35ddf61ba68ecda
- https://github.com/activepieces/activepieces/pull/12721
- https://github.com/activepieces/activepieces/releases/tag/0.82.0
- https://github.com/activepieces/activepieces/security/advisories/GHSA-7qx9-q4xx-
FAQ
What is CVE-2026-73082?
CVE-2026-73082 is a documented vulnerability. Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request ...
How severe is CVE-2026-73082?
CVSS scoring is not yet available for CVE-2026-73082. Check NVD for updates.
Is there a patch for CVE-2026-73082?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.