LOW
anubissbe
CVE published 2026-08-09
CVE-2026-19340
A low-severity SSRF vulnerability was identified in anubissbe ProjectHub-Mcp up to 5.0.0, affecting an unknown function in the backend-fix/complete_backend.js file of the Webhooks API component. The manipulation of the 'url' argument can cause a server-side request forgery. Remote exploitation is possible. The project was informed of the problem early through an issue report but has not responded yet. Sec [truncated]