---
id: CVE-2026-86122
title: >-
  Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs,
  allowing authenticated users to configure arbitrary destinations
summary: >-
  Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs,
  allowing authenticated users to configure arbitrary destinations. Attackers
  can point these URLs at internal services and cloud metadata endpoints to
  perform ser…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: rowboatlabs
product: rowboat
affected:
  - rowboat <= 0.9.1
published: '2026-09-05'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:46.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86122'
references:
  - url: 'https://github.com/rowboatlabs/rowboat'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/lib/agents-runtime/agent-tools.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/use-cases/projects/add-custom-mcp-server.use-case.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rowboatlabs/rowboat/issues/621'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rowboat-through-0.9.1-server-side-request-forgery-via-custom-mcp-server
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00372
epssPercentile: 0.28354
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:39:28.594338Z'
ingestedAt: '2026-09-06T07:51:56.257Z'
---

## Overview

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
