FrontMCP and mcp-from-openapi SSRF Fix Bypass
A bypass vulnerability in FrontMCP and mcp-from-openapi allows an attacker to trigger requests from the server to localhost or private services during tool generation. This affects hosted or multi-user FrontMCP deployments where users can import or configure OpenAPI specs.