๐Ÿ” CVE Alert

CVE-2026-19374

HIGH 7.3

adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-918
Vendor adafap
Product api-mcp
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for adafap api-mcp

Be the first to know when new high vulnerabilities affecting adafap api-mcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

adafap / api-mcp
92b9a5d04acfec165c7d4ef852496593aa87be06

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387258 vuldb.com: https://vuldb.com/vuln/387258/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19374 vuldb.com: https://vuldb.com/submit/866272 github.com: https://github.com/adafap/api-mcp/issues/4 github.com: https://github.com/adafap/api-mcp/

Credits

๐Ÿ” gongyanyu05 (VulDB User) VulDB CNA Team