CVE-2026-19367 | NocteDefensor LudusMCP 1.0.24 read_range_config src/tools/rangeConfig.ts Source server-side request forgery
A vulnerability was found in NocteDefensor LudusMCP 1.0.24. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery.
This vulnerability is listed as CVE-2026-19367. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More