CVE-2026-19040: Server-side request forgery in MissionSquad mcp-api
A server-side request forgery vulnerability was found in MissionSquad mcp-api up to version 1.11.9 in the src/services/dcrClients.ts file. The issue was fixed in version 1.11.10.
Disclosed 6 August 2026 · Record updated 13 September 2026
Impact
Server-side request forgery vulnerability affecting mcp-api versions up to 1.11.9
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19040
