What is CVE-2026-19375?
CVE-2026-19375 is a server-side request forgery (SSRF) vulnerability in dmitriiweb article-scraper-mcp 1.0.0, affecting the `fetch_article` function in `news_scraper_mcp/server.py` via manipulation of the `url` argument. The flaw allows remote exploitation, potentially enabling attackers to make unauthorized requests from the server. Users are advised to disable the plugin or await a vendor-issued patch.
Azərbaycanca: Bu CVE-2026-19375, dmitriiweb article-scraper-mcp 1.0.0 plagini daxilində server-side request forgery (SSRF) zəifliyidir. Zəiflik `news_scraper_mcp/server.py` faylındakı `fetch_article` funksiyasında `url` arqumentinin manipulyasiyası nəticəsində yaranır və uzaqdan hücuma imkan verir. İstifadəçilərə plaqini müvəqqəti dayandırmaq və ya vendor tərəfindən yeniləmə təmin olunanadək diqqətli olmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which component is affected by CVE-2026-19375?
The vulnerability is in the dmitriiweb article-scraper-mcp 1.0.0 plugin, specifically within the `fetch_article` function in the `news_scraper_mcp/server.py` file.
What temporary measure is recommended regarding CVE-2026-19375?
Users are advised to temporarily disable the plugin or exercise caution until a patch is provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.