GHSA-crh9-3gjh-m6gc
MEDIUMCVE-2026-5832A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyzeapispec/generatetestscenarios/testhttpendpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and
- Affected
- >=0, <= 0.2.1
- Fixed in
- not stated
- Weakness
- CWE-918
- Published
- 2026-04-09
- Source
- osv