CVE-2026-19770: Server-Side Request Forgery in feedmob fm-mcp-servers
CVE-2026-19770 is a server-side request forgery (SSRF) vulnerability in feedmob fm-mcp-servers version 0.0.3. The flaw exists in the downloadReport function of the Download Endpoint component, where manipulation of the downloadUrl argument allows SSRF attacks. Exploitation requires local access to the environment. The vulnerability has a medium severity score of 4.8 and public exploit code is available. The vendor has not yet responded or issued a patch.
AI Analysis
Technical Summary
The vulnerability CVE-2026-19770 affects feedmob fm-mcp-servers version 0.0.3 in the downloadReport function located in src/smadex-reporting/src/index.ts. An attacker with local access can manipulate the downloadUrl parameter to perform server-side request forgery, potentially causing the server to make unintended HTTP requests. The vulnerability is confirmed and publicly disclosed with a CVSS 4.8 (medium) score. No official patch or remediation has been provided by the vendor as of the publication date.
Potential Impact
An attacker with local access can exploit this SSRF vulnerability to make the server send crafted HTTP requests to internal or external systems. This could lead to information disclosure or interaction with internal services not otherwise accessible. However, the attack requires local environment access, limiting remote exploitation risk. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Since exploitation requires local access, restricting local user permissions and network access can reduce risk. Monitor for updates from the vendor and apply any future patches promptly. Avoid exposing the vulnerable version (0.0.3) in production environments until fixed.
CVE-2026-19770: Server-Side Request Forgery in feedmob fm-mcp-servers
Description
CVE-2026-19770 is a server-side request forgery (SSRF) vulnerability in feedmob fm-mcp-servers version 0.0.3. The flaw exists in the downloadReport function of the Download Endpoint component, where manipulation of the downloadUrl argument allows SSRF attacks. Exploitation requires local access to the environment. The vulnerability has a medium severity score of 4.8 and public exploit code is available. The vendor has not yet responded or issued a patch.
CVSS v4.0
Score 4.8medium
Affected software
feedmob
fm-mcp-servers
pkg:github/feed-mob/fm-mcp-serverscpe:2.3:a:feedmob:fm-mcp-servers:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-19770 affects feedmob fm-mcp-servers version 0.0.3 in the downloadReport function located in src/smadex-reporting/src/index.ts. An attacker with local access can manipulate the downloadUrl parameter to perform server-side request forgery, potentially causing the server to make unintended HTTP requests. The vulnerability is confirmed and publicly disclosed with a CVSS 4.8 (medium) score. No official patch or remediation has been provided by the vendor as of the publication date.
Potential Impact
An attacker with local access can exploit this SSRF vulnerability to make the server send crafted HTTP requests to internal or external systems. This could lead to information disclosure or interaction with internal services not otherwise accessible. However, the attack requires local environment access, limiting remote exploitation risk. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Since exploitation requires local access, restricting local user permissions and network access can reduce risk. Monitor for updates from the vendor and apply any future patches promptly. Avoid exposing the vulnerable version (0.0.3) in production environments until fixed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-13T17:13:15.028Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7e7965bf8831d5393e1ea8
Added to database: 08/14/2026, 02:11:49 UTC
Last enriched: 08/21/2026, 14:07:52 UTC
Last updated: 09/27/2026, 13:47:43 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.