What is CVE-2026-19957?
CVE-2026-19957 affects graphlit-mcp-server 1.0.1, allowing Server-Side Request Forgery (SSRF) via the url argument in the fetch function of the ssrf-test Endpoint. It is exploitable remotely, requiring immediate patching or disabling of the affected Endpoint.
Azərbaycanca: CVE-2026-19957 graphlit-mcp-server 1.0.1-də aşkarlanıb. Bu, ssrf-test Endpoint-də fetch funksiyasında url arqumenti vasitəsilə server tərəfli sorğu saxtakarlığına (SSRF) səbəb olur. Uzaqdan istismar mümkündür, dərhal yamaq tətbiq edilməli və ya təsirlənən Endpoint deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which version of graphlit-mcp-server is affected by CVE-2026-19957 and how can it be mitigated?
This vulnerability affects graphlit-mcp-server version 1.0.1. Immediate patching or disabling the affected ssrf-test Endpoint is required.
What is the exploitation type and vector of CVE-2026-19957?
It is a Server-Side Request Forgery (SSRF) vulnerability, exploitable remotely via the url argument in the fetch function of the ssrf-test Endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.