CVE-2026-108542: 021is elvix-sdk MCP Request index.ts server-side request forgery
A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulation of the argument path results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
021is elvix-sdk versions up to and including 0.10.1 are identified as affected. The issue is in the MCP Request Handler associated with src/mcp/index.ts.
What access does an attacker need?
The vulnerability is remotely exploitable with low attack complexity, but the supplied severity vector indicates that the attacker requires low-level privileges. No user interaction is required.
What is the impact of successful exploitation?
Manipulating the path argument can cause server-side request forgery, allowing requests to be made from the affected server. The provided vector rates confidentiality, integrity, and availability impact as low.
Is public exploit information available?
Yes. The exploit has been made public and could be used.