CVE-2026-19770 | feedmob fm-mcp-servers 0.0.3 Download Endpoint index.ts downloadReport downloadUrl server-side request forgery (Issue 198)
A vulnerability classified as critical has been found in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-19770. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More