PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5607 imprvhub CVE debrief

A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Users should assess the vulnerability and apply patches or mitigations as necessary.

Vendor
imprvhub
Product
mcp-browser-agent
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of imprvhub mcp-browser-agent up to 0.8.0 should assess the vulnerability and apply patches or mitigations as necessary. This includes operators, platform administrators, vulnerability management teams, and security teams who need to evaluate the impact on their environments.

Technical summary

The vulnerability is in the CallToolRequestSchema function of the src/handlers.ts file in the imprvhub mcp-browser-agent up to 0.8.0. This function is part of the URL Parameter Handler component. The vulnerability allows for server-side request forgery via manipulation of the request.params.name and request.params.arguments. The attack can be carried out remotely. To defend against this vulnerability, users should assess the vulnerability and apply patches or mitigations as necessary. This includes verifying the integrity of requests handled by the CallToolRequestSchema function and ensuring that proper validation and sanitization of input parameters are in place to prevent unauthorized requests. Additionally, implementing compensating controls such as web application firewalls can help mitigate the risk. It is also recommended to monitor for suspicious activity and review relevant logs for exposed assets that need extra review.

Defensive priority

Low priority due to CVSS score of 2.1 and lack of known exploit usage.

Recommended defensive actions

  • Inventory and assess instances of imprvhub mcp-browser-agent up to 0.8.0
  • Apply patches or updates if available
  • Implement compensating controls such as web application firewalls
  • Monitor for suspicious activity
  • Verify vendor remediation status
  • Review relevant logs for exposed assets that need extra review
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-04-06T01:16:39.817Z and was last modified on 2026-07-24T09:10:00.153Z. The NVD entry is currently Deferred. The vulnerability details are based on the provided source corpus. Further verification and defensive measures are recommended.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T01:16:39.817Z and has not been modified since then. The NVD entry is currently Deferred.