A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/init.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It is recommended to change the configuration settings. The vendor explains: "For deployments where SSRF protection is required, I recommend routing all HTTP(S) requests through an SSRF-safe proxy server. This approach mitigates the vulnerability without requiring changes to the mcp-florence2 source code."
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19984.json"
}{
"extracted_events": [
{
"introduced": "0.3.0"
},
{
"last_affected": "0.3.0"
},
{
"introduced": "0.3.1"
},
{
"last_affected": "0.3.1"
},
{
"introduced": "0.3.2"
},
{
"last_affected": "0.3.2"
},
{
"introduced": "0.3.3"
},
{
"last_affected": "0.3.3"
},
{
"introduced": "0.3.4"
},
{
"last_affected": "0.3.4"
},
{
"introduced": "0.3.5"
},
{
"last_affected": "0.3.5"
},
{
"introduced": "0.3.6"
},
{
"last_affected": "0.3.6"
},
{
"introduced": "0.3.7"
},
{
"last_affected": "0.3.7"
},
{
"introduced": "0.3.8"
},
{
"last_affected": "0.3.8"
},
{
"introduced": "0.3.9"
},
{
"last_affected": "0.3.9"
},
{
"introduced": "0.3.10"
},
{
"last_affected": "0.3.10"
},
{
"introduced": "0.3.11"
},
{
"last_affected": "0.3.11"
},
{
"introduced": "0.3.12"
},
{
"last_affected": "0.3.12"
},
{
"introduced": "0.3.13"
},
{
"last_affected": "0.3.13"
}
],
"source": "AFFECTED_FIELD"
}