CVE-2026-19340 | anubissbe ProjectHub-Mcp up to 5.0.0 Webhooks API complete_backend.js url server-side request forgery (Issue 176)
A vulnerability was found in anubissbe ProjectHub-Mcp up to 5.0.0. It has been classified as critical. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery.
This vulnerability is registered as CVE-2026-19340. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More