CVE-2026-19375: dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery
A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetcharticle of the file newsscrapermcp/server.py. The manipulation of the argument url results in server-side request forgery. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19375?
CVE-2026-19375 has a medium severity rating of 6.3.
What type of vulnerability is CVE-2026-19375?
CVE-2026-19375 is classified as a server-side request forgery (SSRF) vulnerability.
How can I mitigate CVE-2026-19375?
Mitigation for CVE-2026-19375 involves validating and sanitizing user input for the 'url' parameter in the fetch_article function.
What impact can CVE-2026-19375 have on my system?
Exploitation of CVE-2026-19375 can lead to unauthorized access to internal services and potential data leakage.
Which software is affected by CVE-2026-19375?
CVE-2026-19375 affects the dmitriiweb article-scraper-mcp version 1.0.0.