Zurück zur CVE-Übersicht
CVE-2026-14748
MEDIUM(6.3)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Risk Signal Score26/100 — MITTEL
- CVSS 6.3 — Mittel
- Weniger als 24 Stunden alt
Beschreibung
A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Referenzen
- https://github.com/AIAnytime/Awesome-MCP-Server/
- https://github.com/AIAnytime/Awesome-MCP-Server/issues/34
- https://github.com/AIAnytime/Awesome-MCP-Server/issues/35
- https://vuldb.com/cve/CVE-2026-14748
- https://vuldb.com/submit/849289
- https://vuldb.com/submit/849300
- https://vuldb.com/vuln/376334
- https://vuldb.com/vuln/376334/cti