Server-side Request Forgery Vulnerability in Graphlit MCP Server by Graphlit
CVE-2026-19957
Key Information:
- Vendor
Graphlit
- Status
- Vendor
- CVE Published:
- 16 August 2026
Badges
What is CVE-2026-19957?
A vulnerability has been discovered in version 1.0.1 of the Graphlit MCP Server, specifically within the fetch function in the src/tools.ts file associated with the ssrf-test endpoint. This vulnerability allows for potential server-side request forgery, enabling attackers to manipulate URL parameters to send requests on behalf of the server. The vulnerability is susceptible to remote exploitation and has publicly available exploits. Despite early notification through an issue report, the Graphlit team has not yet responded to this critical security concern.
Affected Version(s)
graphlit-mcp-server 1.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
