CVE-2026-58201

Source
https://cve.org/CVERecord?id=CVE-2026-58201
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58201.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-58201
Aliases
Published
2026-09-15T16:48:58Z
Modified
2026-09-17T03:46:56Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Lokka: Azure Resource Manager URL path validation issue
Details

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can alter URL authority parsing and cause an Azure Resource Manager bearer token to be sent to an unintended host. This issue is fixed in version 2.1.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58201.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "2.1.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/merill/lokka

Affected ranges

Type
GIT
Repo
https://github.com/merill/lokka
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58201.json"