Server-Side Request Forgery in Aliyun AlibabaCloud DataWorks MCP Server
CVE-2026-19339

5.3MEDIUM

Key Information:

Vendor

Aliyun

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19339?

A security flaw has been identified in the AlibabaCloud DataWorks MCP Server impacting versions up to 1.0.43. The vulnerability is found in the ReadResourceRequestSchema function within the initResources.ts file, where an improper handling of the request.params.uri argument could enable a remote attacker to perform a server-side request forgery (SSRF). This fault allows attackers to make unauthorized requests, potentially accessing sensitive internal services. Despite early notification to the developers about this issue via an issue report, there has been no response addressing the vulnerability.

Affected Version(s)

alibabacloud-dataworks-mcp-server 1.0.0

alibabacloud-dataworks-mcp-server 1.0.1

alibabacloud-dataworks-mcp-server 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
VulDB CNA Team
.