THREAT OPS › Threat News › [NVD] CVE-2026-19340 (MEDIUM 6.3) — A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the
[NVD] CVE-2026-19340 (MEDIUM 6.3) — A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the
CVE-2026-19340 CVSS: 6.3 MEDIUM Published: 2026-08-09T07:17:04.193
A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the
Indicators of compromise
- CVE-2026-19340cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19340