What is CVE-2026-74842?
CVE-2026-74842 is a server-side request forgery (SSRF) vulnerability in Kira-Pgr PromptShopMCP, affecting the download_image function in server.py. Improper handling of the image_url argument can allow attackers to manipulate server-side requests. Users should immediately apply updates to mitigate the risk.
Azərbaycanca: CVE-2026-74842 Kira-Pgr PromptShopMCP məhsulunda server-side request forgery (SSRF) zəifliyidir. Bu zəiflik server.py faylındakı download_image funksiyasında image_url arqumentinin düzgün yoxlanılmaması səbəbindən baş verir. Təsirə məruz qalan sistemlərdə təcili olaraq müvafiq proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which function of PromptShopMCP was CVE-2026-74842 discovered?
The vulnerability was discovered in the download_image function in the server.py file.
What type of security vulnerability is CVE-2026-74842?
It is a server-side request forgery (SSRF) vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.