CyberRota Analysis
AI-GeneratedTerraform-mcp-server versions prior to 1.1.0 are susceptible to a server-side request forgery vulnerability that enables unauthenticated remote clients to redirect API requests and authorization tokens to malicious endpoints. This could lead to unauthorized access and potential data compromise. Organizations using affected versions should prioritize upgrading to version 1.1.0 to mitigate the risk.
Original NVD Description
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.