Server-Side Request Forgery in gomarble-ai facebook-ads-mcp-server
CVE-2026-19956

5.3MEDIUM

Key Information:

Vendor
CVE Published:
16 August 2026

What is CVE-2026-19956?

A vulnerability has been identified in gomarble-ai's facebook-ads-mcp-server version 0.1.0, specifically in the fetch_pagination_url function located in server.py. This flaw allows an attacker to exploit the application and launch a server-side request forgery (SSRF) attack remotely. To mitigate the potential risks associated with this vulnerability, it is essential to apply the recommended patch, identified by the commit hash 4e53875aa22e8991c2fa4a7660d86e1caba66659.

Affected Version(s)

facebook-ads-mcp-server 0.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TianyuLi (VulDB User)
.