VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-19375Medium· 6.3
1mo ago

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forge…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-19374High· 7.3
1mo ago

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation o…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-19373Medium· 5.3
1mo ago

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl c…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-12372Low· 3.7
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…

▾ Sunlitnltk · nltkEPSS 0.31%via NVD
CVE-2026-19369Medium· 5.3
1mo ago

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-19367Medium· 6.3
1mo ago

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-19352Low· 3.1
1mo ago

A vulnerability was determined in mifi lossless-cut up to 3.69.0

A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to se…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-19340Medium· 6.3
1mo ago

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side …

▾ SunlitEPSS 0.40%via NVD
CVE-2026-19339Medium· 6.3
1mo ago

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument req…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-19337Medium· 5.3
1mo ago

A vulnerability was determined in adenot mcp-google-search up to 0.3.1

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request …

▾ SunlitEPSS 0.16%via NVD
CVE-2026-67620High· 7.7PoC
1mo ago

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba …

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba …

▾ MidnightEPSS 0.46%via NVD
CVE-2026-17597Low· 2.7
1mo ago

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email …

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.23%via NVD
CVE-2026-47664None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `export…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-47662None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller w…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-47660None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explic…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-47659None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async ex…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-16637Medium· 6.5
1mo ago

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-15570None
1mo ago

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the …

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-53983High· 8.6
1mo ago

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to is…

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to is…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-62857None
1mo ago

Fedify is a TypeScript library for building federated server apps powered by ActivityPub

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].h…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-45573Medium· 6.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint wi…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.26%via NVD
CVE-2026-9203High· 8.5
1mo ago

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-55524High· 7.5
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.24%via NVD
CVE-2026-55523High
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.47%via NVD
CVE-2026-71211High· 7.1PoC
1mo ago

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…

▾ Midnightmlflow · mlflowEPSS 0.29%via NVD
CVE-2026-71208Medium· 6.5
1mo ago

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specif…

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specif…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-34966High· 7.6
1mo ago

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.39%via NVD
CVE-2026-70605Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict whi…

▾ Sunlitelectron · electronEPSS 0.32%via NVD
CVE-2026-70595Medium· 4.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…

▾ Sunlitghost · ghostEPSS 0.28%via NVD
CVE-2026-70620Medium· 6.8
1mo ago

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint con…

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint con…

▾ SunlitEPSS 0.46%via NVD
CWE-918 vulnerabilities (CVEs) — page 17 · VulnSea