CVE-2026-19984 PUBLISHED

jkawamoto mcp-florence2 __init__.py get_images server-side request forgery

Assigner: VulDB
Reserved: 16.08.2026 Published: 17.08.2026 Updated: 17.08.2026

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/init.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It is recommended to change the configuration settings. The vendor explains: "For deployments where SSRF protection is required, I recommend routing all HTTP(S) requests through an SSRF-safe proxy server. This approach mitigates the vulnerability without requiring changes to the mcp-florence2 source code."

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor jkawamoto
Product mcp-florence2
Versions
  • Version 0.3.0 is affected
  • Version 0.3.1 is affected
  • Version 0.3.2 is affected
  • Version 0.3.3 is affected
  • Version 0.3.4 is affected
  • Version 0.3.5 is affected
  • Version 0.3.6 is affected
  • Version 0.3.7 is affected
  • Version 0.3.8 is affected
  • Version 0.3.9 is affected
  • Version 0.3.10 is affected
  • Version 0.3.11 is affected
  • Version 0.3.12 is affected
  • Version 0.3.13 is affected

Credits

  • TianyuLi (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Server-Side Request Forgery CWE