CVE-2026-19770
Last modified
CVE-2026-19770 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| feedmob | fm-mcp-servers | 0.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19770?
How severe is CVE-2026-19770?
How do I fix CVE-2026-19770?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19765A security flaw has been discovered in eyaushev swagger-test…6.3
- CVE-2026-19766An authentication bypass vulnerability exists in the underly…9.6
- CVE-2026-19767A weakness has been identified in itsourcecode Hospital Mana…6.3
- CVE-2026-19768Improper control of generation of code ('Code Injection') in…8.1
- CVE-2026-19769The Ninja Forms – The Contact Form Builder That Grows With Y…7.2
- CVE-2026-1977A security vulnerability has been detected in isaacwasserman…6.3
- CVE-2026-19771A vulnerability was identified in Baicells EG3661M BaiCE_BQ6…7.2
- CVE-2026-19773libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds…9.8
- CVE-2026-19774BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution…7.1
- CVE-2026-19778The WPMR Google Feed Manager for WooCommerce – Sell on Googl…6.5
- CVE-2026-1978A vulnerability was detected in kalyan02 NanoCMS up to 0.4. …7.5
- CVE-2026-19780Koha Eval Code Injection Remote Code Execution Vulnerability…8.8
Are you affected by CVE-2026-19770?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
