Server-Side Request Forgery Vulnerability in PhialsBasement KoboldCPP-MCP-Server
CVE-2026-19373

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19373?

A vulnerability has been detected in the PhialsBasement KoboldCPP-MCP-Server version 1.0.0, specifically within the function makeRequest of the BaseConfigSchema component in src/index.ts. This flaw allows an attacker to manipulate the apiUrl argument, resulting in potential server-side request forgery. Such an attack can be executed on the local host, posing a significant risk to the application. Despite being made aware of the issue through an early report, no action has been taken by the project maintainers.

Affected Version(s)

KoboldCPP-MCP-Server 1.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.