What is CVE-2026-19369?
CVE-2026-19369 is a Server-Side Request Forgery (SSRF) vulnerability in KS-GEN-AI jira-mcp-server 0.2.0. It exists in the `axios.get` function within `src/index.ts`, where improper validation of the `imageUrl` argument in the `add_attachment_from_public_url` component allows a local attacker to make unauthorized server-side requests. Immediate patching is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-19369 KS-GEN-AI jira-mcp-server 0.2.0 versiyasında aşkar edilmiş Server-Side Request Forgery (SSRF) zəifliyidir. Bu, `src/index.ts` faylındakı `axios.get` funksiyasında `imageUrl` parametrinin düzgün yoxlanılmaması səbəbindən baş verir və təcavüzkarın lokal şəkildə serveri aldadaraq icazəsiz sorğular göndərməsinə imkan yaradır. Zəiflikdən qorunmaq üçün dərhal müvafiq komponenti yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which version was CVE-2026-19369 discovered?
CVE-2026-19369 was discovered in KS-GEN-AI jira-mcp-server version 0.2.0.
What should be done to mitigate CVE-2026-19369?
Immediate patching is recommended to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.