Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Server-Side Request Forgery in mcp-dominican-layer

Multiple server-side request forgery vulnerabilities were discovered in EnzoVezzaro's mcp-dominican-layer project, affecting the parse-csv and parse-pdf tools through manipulation of csvUrl and pdfUrl arguments. The vulnerabilities have been disclosed publicly and the vendor has not yet responded.

Disclosed 13 August 2026 · Record updated 13 September 2026

Impact

Server-side request forgery vulnerabilities in CSV and PDF parsing functions allowing remote attacks

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19751
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19752