CVE-2026-19369: KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component addattachmentfrompublicurl. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19369?
The severity of CVE-2026-19369 is medium with a score of 5.3.
How do I fix CVE-2026-19369?
To fix CVE-2026-19369, ensure proper input validation and sanitization for the imageUrl argument in the add_attachment_from_public_url function.
What type of vulnerability is CVE-2026-19369?
CVE-2026-19369 is categorized as a server-side request forgery (SSRF) vulnerability.
What component is affected by CVE-2026-19369?
CVE-2026-19369 affects the axios.get function in the add_attachment_from_public_url method of the KS-GEN-AI jira-mcp-server.
What software version is vulnerable in CVE-2026-19369?
The vulnerable version of the software affected by CVE-2026-19369 is KS-GEN-AI jira-mcp-server version 0.2.0.