← All scanned servers

Trust Card · Static snapshot

cloudflare__mcp-server-cloudflare D

43/100 · 105 findings (21 critical) · scope excessive · Ranked #44 of 53 scanned.

Scanned 2026-09-09 · engine v0.1.0 (8 regex rules, OWASP-mapped) · upstream cloudflare/mcp-server-cloudflare @ db90847 (2026-08-31)

Score breakdown

security 0
permissions 35
provenance 80
reliability 85
stability 90

Score constrained by 21 critical and 84 high-severity findings.

Fix first (105 critical/high)

SeverityRuleFindingRemediation
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/ai-gateway/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/auditlogs/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/autorag/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/browser-rendering/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/cloudflare-one-casb/worker-configuration.d.ts:3051
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/demo-day/worker-configuration.d.ts:3039
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/dex-analysis/worker-configuration.d.ts:3053
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/dns-analytics/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/docs-ai-search/worker-configuration.d.ts:3052
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/graphql/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/logpush/worker-configuration.d.ts:3055
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/radar/worker-configuration.d.ts:3053
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/sandbox-container/server/container-tools.ts:68
Evidence: content: [{ type: 'text', text: await getUserContainer(context).container_exec(args) }],
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/sandbox-container/server/userContainer.ts:84
Evidence: async container_exec(params: ExecParams): Promise<string> {
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/sandbox-container/worker-configuration.d.ts:3072
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/workers-bindings/worker-configuration.d.ts:3061
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/workers-builds/worker-configuration.d.ts:3061
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
apps/workers-observability/worker-configuration.d.ts:3067
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
packages/eval-tools/worker-configuration.d.ts:3036
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
packages/mcp-common/worker-configuration.d.ts:3036
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
CRITICALAT-SEC-003 (ASI02)Unbounded Dynamic Shell Execution
packages/mcp-observability/worker-configuration.d.ts:3036
Evidence: exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Strictly restrict shell execution to an immutable allowlist of binary commands with explicit argument arrays, or execute inside microVM sandboxes.
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/ai-gateway/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/ai-gateway/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/ai-gateway/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/ai-gateway/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/auditlogs/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/auditlogs/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/auditlogs/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/auditlogs/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/autorag/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/autorag/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/autorag/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/autorag/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/browser-rendering/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/browser-rendering/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/browser-rendering/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/browser-rendering/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/cloudflare-blog/src/tools/blog.tools.ts:25
Evidence: const res = await fetch(url)
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/cloudflare-one-casb/worker-configuration.d.ts:320
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/cloudflare-one-casb/worker-configuration.d.ts:416
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/cloudflare-one-casb/worker-configuration.d.ts:1854
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/cloudflare-one-casb/worker-configuration.d.ts:10933
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/frontend/script.js:141
Evidence: async function retryFetch(url, options, maxRetries = 3) {
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/frontend/script.js:144
Evidence: const response = await fetch(url, options)
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/worker-configuration.d.ts:308
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/worker-configuration.d.ts:404
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/worker-configuration.d.ts:1842
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/demo-day/worker-configuration.d.ts:10921
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dex-analysis/src/warp_diag_reader.ts:79
Evidence: const res = await fetch(url, { headers })
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dex-analysis/worker-configuration.d.ts:322
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dex-analysis/worker-configuration.d.ts:418
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dex-analysis/worker-configuration.d.ts:1856
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dex-analysis/worker-configuration.d.ts:10935
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dns-analytics/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dns-analytics/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dns-analytics/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/dns-analytics/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/docs-ai-search/worker-configuration.d.ts:321
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/docs-ai-search/worker-configuration.d.ts:417
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/docs-ai-search/worker-configuration.d.ts:1855
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/docs-ai-search/worker-configuration.d.ts:10934
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/graphql/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/graphql/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/graphql/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/graphql/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/logpush/worker-configuration.d.ts:324
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/logpush/worker-configuration.d.ts:420
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/logpush/worker-configuration.d.ts:1858
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/logpush/worker-configuration.d.ts:10937
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/src/tools/radar.tools.ts:163
Evidence: const response = await fetch(url.toString(), {
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/src/tools/url-scanner.tools.ts:39
Evidence: const res = await fetch(url.toString(), {
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/worker-configuration.d.ts:322
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/worker-configuration.d.ts:418
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/worker-configuration.d.ts:1856
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/radar/worker-configuration.d.ts:10935
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/sandbox-container/server/containerHelpers.ts:74
Evidence: return fetch(url, request.clone() as Request)
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/sandbox-container/worker-configuration.d.ts:341
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/sandbox-container/worker-configuration.d.ts:437
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/sandbox-container/worker-configuration.d.ts:1875
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/sandbox-container/worker-configuration.d.ts:10954
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-bindings/worker-configuration.d.ts:330
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-bindings/worker-configuration.d.ts:426
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-bindings/worker-configuration.d.ts:1864
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-bindings/worker-configuration.d.ts:10943
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-builds/worker-configuration.d.ts:330
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-builds/worker-configuration.d.ts:426
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-builds/worker-configuration.d.ts:1864
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-builds/worker-configuration.d.ts:10943
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-observability/worker-configuration.d.ts:336
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-observability/worker-configuration.d.ts:432
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-observability/worker-configuration.d.ts:1870
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
apps/workers-observability/worker-configuration.d.ts:10949
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/eval-tools/worker-configuration.d.ts:305
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/eval-tools/worker-configuration.d.ts:401
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/eval-tools/worker-configuration.d.ts:1839
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/eval-tools/worker-configuration.d.ts:10918
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-common/src/cloudflare-api.ts:51
Evidence: const response = await fetch(url, {
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-common/worker-configuration.d.ts:300
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-common/worker-configuration.d.ts:398
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-common/worker-configuration.d.ts:1838
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-common/worker-configuration.d.ts:10938
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-observability/worker-configuration.d.ts:300
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-observability/worker-configuration.d.ts:398
Evidence: declare function fetch(input: RequestInfo | URL, init?: RequestInit<RequestInitCfProperties>): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-observability/worker-configuration.d.ts:1838
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).
HIGHAT-SEC-006 (LLM06)Unfiltered SSRF / Arbitrary Network Egress
packages/mcp-observability/worker-configuration.d.ts:10938
Evidence: fetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
Define an explicit egress domain allowlist and block private IP ranges (127.0.0.1, 10.0.0.0/8, 169.254.169.254).

Permissions

Scope: excessive · Shell: enabled · Network egress: yes · File deletion: none · Human approval: none

Provenance

License: Apache-2.0 · Lockfile: yes · Security policy: no · Signals: unverified origin

Independently scanned by the AgentTrust registry (not self-reported by the project). Static analysis only — no code executed, findings need human triage, counts may include test/example code. Static snapshot; re-scan before relying on it: npx @eulogik/agenttrust scan https://github.com/cloudflare/mcp-server-cloudflare. Scores move with every upstream commit; pages refresh weekly. How scoring works.