Server-Side Request Forgery in Aliyun AlibabaCloud DataWorks MCP Server
CVE-2026-19339
5.3MEDIUM
What is CVE-2026-19339?
A security flaw has been identified in the AlibabaCloud DataWorks MCP Server impacting versions up to 1.0.43. The vulnerability is found in the ReadResourceRequestSchema function within the initResources.ts file, where an improper handling of the request.params.uri argument could enable a remote attacker to perform a server-side request forgery (SSRF). This fault allows attackers to make unauthorized requests, potentially accessing sensitive internal services. Despite early notification to the developers about this issue via an issue report, there has been no response addressing the vulnerability.
Affected Version(s)
alibabacloud-dataworks-mcp-server 1.0.0
alibabacloud-dataworks-mcp-server 1.0.1
alibabacloud-dataworks-mcp-server 1.0.2
