THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19374 (HIGH 7.3) — A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side req

[NVD] CVE-2026-19374 (HIGH 7.3) — A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side req

highnvdPublished 2026-08-09

CVE-2026-19374 CVSS: 7.3 HIGH Published: 2026-08-09T23:16:36.487

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19374