What is CVE-2026-19956?
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the `fetch_pagination_url` function within `server.py` of gomarble-ai facebook-ads-mcp-server version 0.1.0. This flaw can be exploited remotely, allowing attackers to make unauthorized requests from the server, potentially bypassing security controls. The issue is addressed in patch `4e53875aa22e8991c2fa4a76`.
Azərbaycanca: gomarble-ai facebook-ads-mcp-server 0.1.0 versiyasının `server.py` faylındakı `fetch_pagination_url` funksiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. Bu boşluq uzaqdan hücum edən şəxsə server tərəfindən saxta sorğular göndərməyə imkan verir və təsirlənən sistemlərdə təhlükəsizlik tədbirlərini yan keçə bilər. Problemin aradan qaldırılması üçün `4e53875aa22e8991c2fa4a76` nömrəli yamaq tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which function is affected by the SSRF vulnerability in gomarble-ai facebook-ads-mcp-server version 0.1.0?
The vulnerability is discovered in the `fetch_pagination_url` function within `server.py`.
Which patch should be applied to fix CVE-2026-19956?
The issue is addressed in patch `4e53875aa22e8991c2fa4a76`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.