Skip to content

MCP connectors cannot point at this AnythingMCP server itself - #882

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/mcp-self-loop-guard
Oct 5, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/mcp-self-loop-guard

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

Found in the daily review (5 Oct).

What happened: on 4 Oct a cloud user created an MCP connector "Claude Etsy" with the URL https://cloud.anythingmcp.com. It imported our own kg_how_to_obtain, and each call re-entered our /mcp and called the connector again. 13,709 calls in two hours (12–14 UTC), 13,686 of them Request timed out after ~60 s each. No outage, but p95 latency for everyone else went from ~600 ms to ~1,100 ms in those hours. This is most of the "Etsy" errors in the weekly report.

Fix: assertNotThisServer() in the MCP client engine, before connecting, for discovery and calls: refuses a URL whose host (with port) is this instance's own SERVER_URL / FRONTEND_URL / CLOUD_PUBLIC_URL, with a message explaining the loop. Another MCP server on the same machine (e.g. localhost:8080 next to localhost:4000) and other AnythingMCP instances stay allowed.

Production check: 3 MCP connectors point at cloud.anythingmcp.com; only the looping one was ever called (the other two have 0 calls).

Tests: 5 new cases in mcp-client.engine.spec.ts.

A cloud user created an MCP connector with the URL cloud.anythingmcp.com.
It imported our own kg_how_to_obtain tool, and every call to it re-entered
our /mcp and called itself again: 13,709 calls in two hours on 4 Oct, each
held for the 60 s timeout, and everyone's p95 nearly doubled.

The MCP client now refuses, before connecting (discovery and calls), a URL
whose host is this instance's own SERVER_URL / FRONTEND_URL /
CLOUD_PUBLIC_URL host, with a message that says why. Host and port are
compared, so another MCP server on the same machine stays allowed on
self-hosted instances. Production: 3 such connectors exist; only the
looping one was ever called.
@keysersoft
keysersoft enabled auto-merge (squash) October 5, 2026 11:45
…oop-guard

# Conflicts:
#	packages/backend/src/connectors/engines/mcp-client.engine.spec.ts
#	packages/backend/src/connectors/engines/mcp-client.engine.ts
@keysersoft
keysersoft merged commit 683d8c4 into main Oct 5, 2026
13 checks passed
@keysersoft
keysersoft deleted the keysersoft/mcp-self-loop-guard branch October 5, 2026 11:48
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant