Server-Side Request Forgery Vulnerability in eyaushev swagger-testcase-mcp
CVE-2026-19765
Key Information:
- Vendor
Eyaushev
- Status
- Vendor
- CVE Published:
- 14 August 2026
Badges
What is CVE-2026-19765?
A security flaw has been identified in eyaushev swagger-testcase-mcp, specifically impacting the loadSource function within the swagger-parser.ts file. This vulnerability allows remote attackers to manipulate requests and exploit the application for server-side request forgery. The issue was reported to the project maintainers, who have yet to address the reported fault. Given the nature of the exploit, it poses significant risks to the security of the application and its users.
Affected Version(s)
swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
