Tools AI Risk Radar ai-incident-0004
Incident record
OGX’s MCP connector accepted unchecked destinations, exposing internal services
- Severity
- High
- Status
- Proof-of-concept
- Type
- Data Leak
- Target
- ogx-ai/ogx (formerly Llama Stack)
- Actor
- researcher
- CVE
- CVE-2026-85666
What happened
The OpenAI-compatible POST /v1/responses endpoint fetched an MCP tool’s server_url without the private-address validation used elsewhere. The researcher demonstrated a request to a loopback listener and described potential access to internal services or cloud metadata, including forwarding supplied bearer tokens. The default starter configuration runs without authentication. The CVE records CVSS 4.0 8.7.
The cited issue and proposed fix remained open at the 10 September check; a released fix was not established from these sources.
Sources
- ogx-ai/ogx issue 6287github.com/ogx-ai/ogx/issues/6287
- NVD, CVE-2026-85666nvd.nist.gov/vuln/detail/CVE-2026-85666
- Proposed OGX fix, PR 6390github.com/ogx-ai/ogx/pull/6390
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026