Server-Side Request Forgery in 021is Elvix-SDK Affects Multiple Versions
CVE-2026-108542
Key Information:
Badges
What is CVE-2026-108542?
A vulnerability exists in the 021is elvix-sdk up to version 0.10.1, specifically in the MCP Request Handler component. This issue stems from improper handling of the argument path in the src/mcp/index.ts file. An attacker can exploit this vulnerability to perform server-side request forgery (SSRF), potentially leading to unauthorized access to backend services. Remote attackers can execute this exploit, as it has been made public. Although the vendor was informed of this vulnerability, there has been no response indicating a resolution or patch.
Affected Version(s)
elvix-sdk 0.10.0
elvix-sdk 0.10.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
