CVE-2026-19339 | aliyun alibabacloud-dataworks-mcp-server up to 1.0.43 initResources.ts ReadResourceRequestSchema request.params.uri server-side request forgery
A vulnerability was found in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43 and classified as critical. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-19339. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More