VYPR
Medium severity6.3OSV Advisory· Published Aug 17, 2026· Updated Aug 20, 2026

CVE-2026-19984

CVE-2026-19984

Description

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It is recommended to change the configuration settings. The vendor explains: "For deployments where SSRF protection is required, I recommend routing all HTTP(S) requests through an SSRF-safe proxy server. This approach mitigates the vulnerability without requiring changes to the mcp-florence2 source code."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • 0.3.0, 0.3.1, 0.3.10, …+ 1 more
    • (no CPE)range: 0.3.0, 0.3.1, 0.3.10, …
    • (no CPE)range: <=0.3.13

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.