THREAT OPS › Threat News › [NVD] CVE-2026-19374 (HIGH 7.3) — A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side req
[NVD] CVE-2026-19374 (HIGH 7.3) — A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side req
CVE-2026-19374 CVSS: 7.3 HIGH Published: 2026-08-09T23:16:36.487
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out
Indicators of compromise
- 92b9a5d04acfec165c7d4ef852496593aa87be06sha1
- CVE-2026-19374cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19374