CVE intelligence

CVE-2026-86122

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations

Published 2026-09-05 · CVSS

medium

NIST record