What is CVE-2026-19337?
CVE-2026-19337 is a Server-Side Request Forgery (SSRF) vulnerability in the adenot mcp-google-search component (up to version 0.3.1), affecting the `read_webpage` function in `src/index.ts` via argument `url` manipulation. Exploitation is limited to local execution, and affected users should apply the available patch immediately.
Azərbaycanca: CVE-2026-19337, adenot mcp-google-search komponentinin 0.3.1 və daha əvvəlki versiyalarında `src/index.ts` faylındakı `read_webpage` funksiyasının `url` arqumentini manipulyasiya etməklə Server-Side Request Forgery (SSRF) zəifliyidir. Bu zəiflik yalnız lokal icrada istismar edilə bilər, təsirlənən istifadəçilər dərhal patchi tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What component and versions are affected by CVE-2026-19337?
This vulnerability exists in the adenot mcp-google-search component, specifically in versions up to 0.3.1.
How can I protect against CVE-2026-19337?
Since exploitation is limited to local execution, affected users should apply the available patch immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.