npm package report

Is api-lab-mcp safe?

1 known vulnerability, worst severity MEDIUM.

cvss
6.9

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-crh9-3gjh-m6gc, the advisory selected below

// advisories

GHSA-crh9-3gjh-m6gc

MEDIUMCVE-2026-5832

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyzeapispec/generatetestscenarios/testhttpendpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and

Affected
>=0, <= 0.2.1
Fixed in
not stated
Weakness
CWE-918
Published
2026-04-09
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 00:41 UTC. The most recent advisory here was published 2026-04-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is api-lab-mcp safe? npm package security report | CyberXYZ