What is CVE-2026-19373?
A server-side request forgery (SSRF) vulnerability has been identified in PhialsBasement KoboldCPP-MCP-Server version 1.0.0. The flaw exists in the makeRequest function in src/index.ts of the BaseConfigSchema component, where manipulation of the apiUrl argument allows unauthorized internal requests. Remote exploitation is possible, potentially leading to unauthorized access to internal resources.
Azərbaycanca: PhialsBasement KoboldCPP-MCP-Server 1.0.0 versiyasında server tərəfli sorğu saxtakarlığı (SSRF) boşluğu aşkarlanıb. Zəiflik BaseConfigSchema komponentinin src/index.ts faylındakı makeRequest funksiyasında apiUrl arqumentinin manipulyasiyası nəticəsində yaranır. İstismar uzaqdan mümkündür, serverin daxili resurslara icazəsiz girişi ilə nəticələnə bilər.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Where is the SSRF vulnerability located in PhialsBasement KoboldCPP-MCP-Server?
The vulnerability exists in the makeRequest function in src/index.ts of the BaseConfigSchema component, caused by manipulation of the apiUrl argument.
What can an attacker gain by exploiting CVE-2026-19373?
Remote exploitation is possible and could lead to unauthorized access to internal resources on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.