VULNRABLE / Vulnerability / CVE-2026-59973

CVE-2026-59973

HIGH LOW mcp-from-openapi GHSA

Exploit verdict: No active-exploit signal

CVSS Score
8
Severity
HIGH
EPSS
Source
GHSA

Summary

FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix

What this means

CVE-2026-59973 is a high-severity vulnerability affecting mcp-from-openapi, rated CVSS 8. Published September 12, 2026.

View full advisory at GHSA →