CVE-2026-108787 | houtini-ai voice-analyser-mcp up to 2.1.1 collect_corpus src/utils/crawler.ts fetch sitemap_url server-side request forgery
A vulnerability identified as critical has been detected in houtini-ai voice-analyser-mcp up to 2.1.1. The affected element is the function fetch of the file src/utils/crawler.ts of the component collect_corpus. Performing a manipulation of the argument sitemap_url results in server-side request forgery.
This vulnerability is known as CVE-2026-108787. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More