Server-Side Request Forgery Vulnerability in KS-GEN-AI Jira-MCP-Server
CVE-2026-19369
4.8MEDIUM
What is CVE-2026-19369?
A vulnerability exists in the KS-GEN-AI jira-mcp-server version 0.2.0, specifically within the add_attachment_from_public_url function in src/index.ts. This flaw arises from improper handling of the imageUrl parameter in the axios.get function, which can lead to server-side request forgery (SSRF) vulnerabilities. Consequently, attackers can craft requests to internal systems by manipulating the imageUrl argument. Despite early reports raising awareness of this issue, the response from the project has been negligible, leaving systems exposed to potential exploitation.
Affected Version(s)
jira-mcp-server 0.2.0
