GHSA-h7xc-4mv8-59fj

Suggest an improvement
Source
https://github.com/advisories/GHSA-h7xc-4mv8-59fj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h7xc-4mv8-59fj/GHSA-h7xc-4mv8-59fj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h7xc-4mv8-59fj
Aliases
  • CVE-2026-7158
Published
2026-04-27T21:31:03Z
Modified
2026-05-06T18:49:22.896568Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
mcp-url-downloader has a Server-Side Request Forgery issue
Details

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function validateurlsafe of the file src/mcpurl_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2026-04-27T21:16:44Z",
    "cwe_ids": [
        "CWE-918"
    ],
    "github_reviewed_at": "2026-05-06T18:39:48Z"
}
References

Affected packages

PyPI / mcp-url-downloader

Package

Name
mcp-url-downloader
View open source insights on deps.dev
Purl
pkg:pypi/mcp-url-downloader

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.1.0

Affected versions

0.*
0.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h7xc-4mv8-59fj/GHSA-h7xc-4mv8-59fj.json"