Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19339

Опубликовано: 09 авг. 2026
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 11%
0.0021
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
github
около 1 месяца назад

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 11%
0.0021
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918