What is CVE-2026-19340?
CVE-2026-19340 is a server-side request forgery (SSRF) vulnerability in anubissbe ProjectHub-Mcp up to version 5.0.0, affecting the Webhooks API component via manipulation of the url argument in `backend-fix/complete_backend.js`. This allows remote exploitation, and users are advised to apply security patches immediately.
Azərbaycanca: CVE-2026-19340, anubissbe ProjectHub-Mcp 5.0.0 və əvvəlki versiyalarında Webhooks API komponentində server-side request forgery (SSRF) zəifliyidir. Bu boşluq remote istismara imkan verir və `backend-fix/complete_backend.js` faylındakı url arqumentinin manipulyasiyası nəticəsində yaranır. İstifadəçilərə təcili olaraq təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which component of ProjectHub-Mcp is affected by CVE-2026-19340?
This SSRF vulnerability affects the Webhooks API component.
Which file is manipulated to exploit CVE-2026-19340?
The vulnerability is exploited by manipulating the url argument in the `backend-fix/complete_backend.js` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.