CVE-2026-19956: gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetchpaginationurl of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
gomarble-ai facebook-ads-mcp-serverto a version that resolves this vulnerability.Fixed in 0.1.0Patch 4e53875aa22e8991c2fa4a7660d86e1caba66659 - Compensating control
Mitigate SSRF risk by restricting outbound network access from the server running gomarble-ai facebook-ads-mcp-server (server.py, function fetch_pagination_url) to only the required destinations, since the vulnerability can be triggered remotely.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19956?
The severity of CVE-2026-19956 is rated as medium with a score of 6.3.
What type of vulnerability is CVE-2026-19956?
CVE-2026-19956 is categorized as a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2026-19956?
To fix CVE-2026-19956, apply the patch identified by the commit 4e53875aa22e8991c2fa4a76.
Who is affected by CVE-2026-19956?
CVE-2026-19956 affects users of gomarble-ai/facebook-ads-mcp-server version 0.1.0.
Can CVE-2026-19956 be exploited remotely?
Yes, CVE-2026-19956 can be exploited remotely.