What is CVE-2026-19984?
CVE-2026-19984 affects jkawamoto/mcp-florence2 up to version 0.3.13, where the `get_images` function in `src/mcp_florence2/__init__.py` improperly handles the `src` argument, leading to a Server-Side Request Forgery (SSRF) vulnerability. The attack can be initiated remotely; users should apply the available patch immediately.
Azərbaycanca: CVE-2026-19984 boşluğu jkawamoto/mcp-florence2 (v0.3.13-ə qədər) kitabxanasında aşkar edilib. __init__.py faylındakı `get_images` funksiyasında `src` arqumentinin manipulyasiyası SSRF (Server-Side Request Forgery) hücumuna səbəb olur. Uzaqdan hücum mümkündür, istifadəçilərə dərhal yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which library is affected by CVE-2026-19984 and what versions are at risk?
CVE-2026-19984 affects the jkawamoto/mcp-florence2 library up to version 0.3.13.
What type of vulnerability is CVE-2026-19984 and how can it be exploited?
CVE-2026-19984 is a Server-Side Request Forgery (SSRF) vulnerability caused by manipulation of the `src` argument in the `get_images` function within the __init__.py file. The attack can be initiated remotely.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.