PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 4.8epss 0.1%
probabilidade de exploração
0.1%top 99% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
PhialsBasement · KoboldCPP-MCP-ServerPoCs públicas encontradas — 1
cve_referencegithub.com/adenot/mcp-google-search/issues/11não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://github.com/adenot/mcp-google-search/issues/11https://github.com/PhialsBasement/KoboldCPP-MCP-Server/https://github.com/PhialsBasement/KoboldCPP-MCP-Server/issues/3https://vuldb.com/cve/CVE-2026-19373https://vuldb.com/submit/866271https://vuldb.com/vuln/387257https://vuldb.com/vuln/387257/cti