YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0004

Incident record

OGX’s MCP connector accepted unchecked destinations, exposing internal services

Severity
High
Status
Proof-of-concept
Type
Data Leak
Target
ogx-ai/ogx (formerly Llama Stack)
Actor
researcher
CVE
CVE-2026-85666

What happened

The OpenAI-compatible POST /v1/responses endpoint fetched an MCP tool’s server_url without the private-address validation used elsewhere. The researcher demonstrated a request to a loopback listener and described potential access to internal services or cloud metadata, including forwarding supplied bearer tokens. The default starter configuration runs without authentication. The CVE records CVSS 4.0 8.7.

The cited issue and proposed fix remained open at the 10 September check; a released fix was not established from these sources.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026