Server-Side Request Forgery Vulnerability in KS-GEN-AI Jira-MCP-Server
CVE-2026-19369

4.8MEDIUM

Key Information:

Vendor

Ks-gen-ai

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19369?

A vulnerability exists in the KS-GEN-AI jira-mcp-server version 0.2.0, specifically within the add_attachment_from_public_url function in src/index.ts. This flaw arises from improper handling of the imageUrl parameter in the axios.get function, which can lead to server-side request forgery (SSRF) vulnerabilities. Consequently, attackers can craft requests to internal systems by manipulating the imageUrl argument. Despite early reports raising awareness of this issue, the response from the project has been negligible, leaving systems exposed to potential exploitation.

Affected Version(s)

jira-mcp-server 0.2.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.