Server-Side Request Forgery Vulnerability in PhialsBasement KoboldCPP-MCP-Server
CVE-2026-19373
4.8MEDIUM
What is CVE-2026-19373?
A vulnerability has been detected in the PhialsBasement KoboldCPP-MCP-Server version 1.0.0, specifically within the function makeRequest of the BaseConfigSchema component in src/index.ts. This flaw allows an attacker to manipulate the apiUrl argument, resulting in potential server-side request forgery. Such an attack can be executed on the local host, posing a significant risk to the application. Despite being made aware of the issue through an early report, no action has been taken by the project maintainers.
Affected Version(s)
KoboldCPP-MCP-Server 1.0.0
