{"apiVersion":"1.0","identifier":"CVE-2026-50143","description":"The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor publisher to use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp tool-loading paths pass this URL to transports in src/mcp/client.ts that attach the victim Authorization bearer token, exposing the Apify API token and enabling access to Actors, stored data, and billable compute. A victim must invoke or inspect the attacker-controlled Actor. This issue is fixed in version 0.10.11.","publishedAt":"2026-08-18T18:17:53","lastModifiedAt":"2026-08-18T20:17:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50143","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","epssProbability":0.00338,"riskScore":0.83,"affectedProduct":"Apify MCP server","affectedVersions":"<0.10.11","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-50143","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-50143","en":"https://www.redsauce.net/en/cves/CVE-2026-50143","fr":"https://www.redsauce.net/fr/cves/CVE-2026-50143","pt":"https://www.redsauce.net/pt/cves/CVE-2026-50143","de":"https://www.redsauce.net/de/cves/CVE-2026-50143","sk":"https://www.redsauce.net/sk/cves/CVE-2026-50143","el":"https://www.redsauce.net/el/cves/CVE-2026-50143"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-50143"}}