Sceawere

Vulnerability Detail

CVE-2026-19340UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ProjectHub-Mcp Webhooks SSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
6h ago
Vendor
anubissbe
Product
ProjectHub-Mcp
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-09T07:17:04.193Z",
  "pubdate": "2026-08-09T07:17:04.193Z",
  "executiveSummary": "An unauthenticated Server-Side Request Forgery (SSRF) vulnerability has been identified in the Webhooks API component of anubissbe ProjectHub-Mcp up to 5.0.0. Specifically, this flaw exists in the backend-fix/complete_backend.js file, where user-supplied input passed to the url argument is processed without adequate validation or sanitization. This flaw permits remote attackers to manipulate the targeted endpoint parameter, forcing the underlying server to initiate arbitrary HTTP or network requests on behalf of the application.\nThe primary risk associated with this vulnerability includes unauthorized interaction with internal network resources, exposure of sensitive metadata services, and potential port scanning of internal infrastructure that is otherwise shielded from the public internet. The attack can be executed remotely without requiring prior authentication or privileged access within the affected system. Exploitation relies entirely on the application's failure to restrict outbound requests originating from the Webhooks API component to trusted domains or explicitly defined endpoints.\nGiven that the vendor has not yet responded to early issue reports regarding this security defect, systems running ProjectHub-Mcp versions up to 5.0.0 remain exposed unless manual hardening controls are enforced at the network or application layer.",
  "technicalDetails": "The vulnerability resides in the backend-fix/complete_backend.js file within the Webhooks API component of anubissbe ProjectHub-Mcp up to 5.0.0. The root cause of the Server-Side Request Forgery (SSRF) is the insecure handling of the url argument. When a webhook is configured or triggered, the application takes the user-supplied url parameter and directly passes it to an underlying HTTP client function without enforcing strict allowlisting, schema validation, or IP address filtering.\nFrom an attack flow perspective, a remote, unauthenticated adversary interacts with the Webhooks API endpoint exposed over the network. By supplying a maliciously crafted URL within the url argument—such as pointing to internal loopback addresses (127.0.0.1 or [::1]), cloud metadata services (e.g., 169.254.169.254), or internal intranet services—the attacker coerces the server hosting ProjectHub-Mcp to issue a request to the specified destination.\nThe payload behavior involves the server executing the outbound request using its own network privileges and context. This allows the attacker to bypass perimeter network defenses, firewall rules, and network segmentation, as the traffic originates from a trusted internal host. Depending on the environment, successful exploitation can lead to the retrieval of confidential internal data, leakage of cloud instance metadata credentials, or interaction with internal administrative interfaces.\nThe affected versions include anubissbe ProjectHub-Mcp up to 5.0.0. The vulnerability requires network exposure of the Webhooks API component, does not mandate authentication or specific user privileges, and can be fully exploited remotely."
}
CVE-2026-19340: ProjectHub-Mcp Webhooks SSRF Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere