What is CVE-2026-19752?
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the `parse-pdf` function of the `src/index.ts` file in EnzoVezzaro mcp-dominican-layer. This issue affects the `pdfUrl` argument and can be exploited remotely. It is recommended to update the library or strictly validate incoming URLs to mitigate the risk.
Azərbaycanca: EnzoVezzaro mcp-dominican-layer proqramının `src/index.ts` faylındakı `parse-pdf` funksiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkarlanıb. Bu, `pdfUrl` arqumenti vasitəsilə uzaqdan istismar oluna bilər. Təsirə məruz qalmamaq üçün kitabxananı yeniləmək və ya daxil olan URL-ləri ciddi şəkildə yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: EnzoVezzaro
FAQ2
In which component was the CVE-2026-19752 vulnerability discovered?
The vulnerability was discovered in the `parse-pdf` function of the `src/index.ts` file in the EnzoVezzaro mcp-dominican-layer application.
What measures are recommended to protect against exploitation of CVE-2026-19752?
It is recommended to update the library or strictly validate incoming URLs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.