Autopsy Series
Would Ethosure have caught this? The Sentry MCP server SSRF
A self-hosted Sentry MCP server accepted a caller-controlled endpoint argument and passed it directly to an HTTP client. Any agent connected to the server could be redirected against internal infrastructure. The fix is not one CVE. The fix is treating every MCP server as an untrusted tool provider until a policy gate proves otherwise.
