CVE-2026-82905 | sdcb chats up to 1.12.0 fetch-tools Endpoint McpController.cs McpController server-side request forgery
A vulnerability was found in sdcb chats up to 1.12.0. It has been declared as critical. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-82905. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More