GHSA-crh9-3gjh-m6gc

Suggest an improvement
Source
https://github.com/advisories/GHSA-crh9-3gjh-m6gc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-crh9-3gjh-m6gc/GHSA-crh9-3gjh-m6gc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-crh9-3gjh-m6gc
Aliases
Published
2026-04-09T03:31:15Z
Modified
2026-04-10T19:41:27Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
api-lab-mcp vulnerable to SSRF
Details

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-10T19:19:34Z",
    "nvd_published_at":  "2026-04-09T02:16:18Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / api-lab-mcp

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-crh9-3gjh-m6gc/GHSA-crh9-3gjh-m6gc.json"