CVE-2026-19040 Details
Description
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This patch is called f068ab4ad6f0907ac7001b995588c2673f11a755. You should upgrade the affected component.
A server-side request forgery (SSRF) vulnerability has been identified in MissionSquad mcp-api versions through 1.11.9. The issue arises in the OAuth Dynamic Client Registration (DCR) flow, where the registration endpoint URL, controlled by the caller, is not properly validated before being used in a server-side POST request. This oversight allows for manipulation that could direct requests to internal or loopback addresses, potentially leading to unauthorized access or information disclosure.
Users should upgrade to MissionSquad mcp-api version 1.11.10, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MissionSquad/mcp-api/issues/42 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/MissionSquad/mcp-api/ | [email protected] | Vendor |
| https://github.com/MissionSquad/mcp-api/commit/f068ab4ad6f0907ac7001b995588c2673f11a755 | [email protected] | Source CodeVendor |
| https://github.com/MissionSquad/mcp-api/issues/42 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/MissionSquad/mcp-api/pull/45 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/MissionSquad/mcp-api/releases/tag/v1.11.10 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-19040 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/863829 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/386459 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/386459/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MissionSquad mcp-api | <= 1.11.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion