Server-Side Request Forgery in anubissbe ProjectHub-Mcp Webhooks API
CVE-2026-19340
5.3MEDIUM
What is CVE-2026-19340?
A vulnerability exists in the anubissbe ProjectHub-Mcp's Webhooks API, specifically in the unknown function located in the backend-fix/complete_backend.js file. This weakness allows manipulation of the URL argument, which can lead to server-side request forgery (SSRF). This issue can be exploited remotely, presenting a significant security risk. Although the project has been notified of the vulnerability through an issue report, no response has been received to date.
Affected Version(s)
ProjectHub-Mcp 5.0
