Server-Side Request Forgery in Proxy API Endpoint of AdaFap API-MCP
CVE-2026-19374

6.9MEDIUM

Key Information:

Vendor

Adafap

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19374?

A security flaw has been identified in the AdaFap API-MCP that affects its Proxy API Endpoint. The vulnerability arises from inadequate validation of user-supplied URLs in the customAxios function located in app/api/proxy/route.ts. This oversight allows attackers to perform server-side request forgery (SSRF) attacks, potentially leading to unauthorized access to internal resources. The product follows a rolling release strategy, thus no specific version details for the fixes have been provided. Although the issue was reported to the developers through an issue tracker, no response has been offered yet.

Affected Version(s)

api-mcp 92b9a5d04acfec165c7d4ef852496593aa87be06

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu05 (VulDB User)
VulDB CNA Team
.