What is CVE-2026-19751?
CVE-2026-19751 is a server-side request forgery (SSRF) flaw in the parse-csv tool of EnzoVezzaro mcp-dominican-layer. The manipulation of the csvUrl argument in the axios.get function within src/index.ts can allow remote attacks. Affected users should apply updates or strengthen input validation immediately.
Azərbaycanca: CVE-2026-19751, EnzoVezzaro mcp-dominican-layer-in parse-csv alətində server-side request forgery (SSRF) zəifliyidir. src/index.ts faylındakı axios.get funksiyasında csvUrl arqumentinin düzgün yoxlanılmaması uzaqdan hücumlara imkan verir. Təsirə məruz qalan versiyaları istifadə edənlər dərhal müvafiq yeniləməni tətbiq etməli və ya giriş validasiyasını gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: EnzoVezzaro
FAQ2
Where is the CVE-2026-19751 vulnerability located?
The vulnerability is located in the parse-csv tool of EnzoVezzaro mcp-dominican-layer, specifically within the axios.get function in the src/index.ts file.
What security issue does CVE-2026-19751 cause?
This vulnerability causes a server-side request forgery (SSRF) issue, as the improper validation of the csvUrl argument allows remote attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.