Server-Side Request Forgery in Proxy API Endpoint of AdaFap API-MCP
CVE-2026-19374
6.9MEDIUM
What is CVE-2026-19374?
A security flaw has been identified in the AdaFap API-MCP that affects its Proxy API Endpoint. The vulnerability arises from inadequate validation of user-supplied URLs in the customAxios function located in app/api/proxy/route.ts. This oversight allows attackers to perform server-side request forgery (SSRF) attacks, potentially leading to unauthorized access to internal resources. The product follows a rolling release strategy, thus no specific version details for the fixes have been provided. Although the issue was reported to the developers through an issue tracker, no response has been offered yet.
Affected Version(s)
api-mcp 92b9a5d04acfec165c7d4ef852496593aa87be06
