GHSA-vmh7-9c7h-2pgg
LOWCVE-2026-7150A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generatefaviconfromurl of the file src/autofavicon/server.py of the component MCP Tool. The manipulation of the argument imageurl results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This pro
- Affected
- <= 1.0.1
- Fixed in
- not stated
- Weakness
- CWE-918
- Published
- 2026-04-27
- Source
- github