What is CVE-2026-19770?
This vulnerability exists in the Download Endpoint component of feedmob fm-mcp-servers version 0.0.3. The manipulation of the `downloadUrl` argument in the `downloadReport` function leads to server-side request forgery (SSRF). It is recommended to restrict the use of this function or validate inputs on affected systems.
Azərbaycanca: Bu zəiflik feedmob fm-mcp-servers 0.0.3 versiyasının Download Endpoint komponentində aşkarlanıb. `downloadReport` funksiyasındakı `downloadUrl` parametrinin manipulyasiyası server-side request forgery (SSRF) hücumuna səbəb olur. Təsirə məruz qalan sistemlərdə bu funksiyadan istifadəni məhdudlaşdırmaq və ya verilənləri yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which product and version are affected by CVE-2026-19770?
This vulnerability exists in the Download Endpoint component of feedmob fm-mcp-servers version 0.0.3.
What security issue does CVE-2026-19770 cause and where is it located?
The manipulation of the `downloadUrl` argument in the `downloadReport` function leads to server-side request forgery (SSRF).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.