Would Ethosure have caught this? The Sentry MCP server SSRF

A self-hosted Sentry MCP server accepted a caller-controlled endpoint argument and passed it directly to an HTTP client. Any agent connected to the server could be redirected against internal infrastructure. The fix is not one CVE. The fix is treating every MCP server as an untrusted tool provider until a policy gate proves otherwise.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.