CVE-2026-19374: Server-Side Request Forgery in adafap api-mcp
CVE-2026-19374 is a server-side request forgery (SSRF) vulnerability in the adafap api-mcp project. It affects the customAxios function in the Proxy API Endpoint component, allowing remote attackers to manipulate the URL argument and potentially cause the server to make unauthorized requests. The product uses a rolling release strategy, so specific affected versions are not clearly defined. The vendor has been informed but has not yet responded or issued a fix. The CVSS 4.0 score rates this vulnerability as medium severity.
AI Analysis
Technical Summary
This vulnerability exists in the adafap api-mcp project up to commit 92b9a5d04acfec165c7d4ef852496593aa87be06, specifically in the customAxios function within app/api/proxy/route.ts. Manipulation of the URL argument in this function can lead to server-side request forgery, enabling an attacker to cause the server to send crafted requests to internal or external resources. The vulnerability can be exploited remotely without authentication or user interaction. Due to the rolling release model, exact affected versions are not specified. The vendor has not yet provided a patch or official remediation guidance.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to induce the server to make arbitrary HTTP requests, potentially accessing internal resources or services not otherwise exposed. This can lead to information disclosure or further attacks depending on the internal network environment. The vulnerability has a medium severity rating with a CVSS 4.0 score of 6.9, reflecting its network attack vector and low complexity but limited impact scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or released a fix, users should monitor the project's official channels for updates. Until a fix is available, consider implementing network-level controls to restrict outbound requests from the affected service to trusted destinations only, if feasible.
CVE-2026-19374: Server-Side Request Forgery in adafap api-mcp
Description
CVE-2026-19374 is a server-side request forgery (SSRF) vulnerability in the adafap api-mcp project. It affects the customAxios function in the Proxy API Endpoint component, allowing remote attackers to manipulate the URL argument and potentially cause the server to make unauthorized requests. The product uses a rolling release strategy, so specific affected versions are not clearly defined. The vendor has been informed but has not yet responded or issued a fix. The CVSS 4.0 score rates this vulnerability as medium severity.
CVSS v4.0
Score 6.9medium
Affected software
cpe:2.3:a:adafap:api-mcp:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the adafap api-mcp project up to commit 92b9a5d04acfec165c7d4ef852496593aa87be06, specifically in the customAxios function within app/api/proxy/route.ts. Manipulation of the URL argument in this function can lead to server-side request forgery, enabling an attacker to cause the server to send crafted requests to internal or external resources. The vulnerability can be exploited remotely without authentication or user interaction. Due to the rolling release model, exact affected versions are not specified. The vendor has not yet provided a patch or official remediation guidance.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to induce the server to make arbitrary HTTP requests, potentially accessing internal resources or services not otherwise exposed. This can lead to information disclosure or further attacks depending on the internal network environment. The vulnerability has a medium severity rating with a CVSS 4.0 score of 6.9, reflecting its network attack vector and low complexity but limited impact scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or released a fix, users should monitor the project's official channels for updates. Until a fix is available, consider implementing network-level controls to restrict outbound requests from the affected service to trusted destinations only, if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-09T07:31:40.909Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a790936bf8831d53969258c
Added to database: 08/09/2026, 23:11:50 UTC
Last enriched: 08/09/2026, 23:29:50 UTC
Last updated: 08/09/2026, 23:29:50 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.