Server-Side Request Forgery in mcp-dominican-layer
Multiple server-side request forgery vulnerabilities were discovered in EnzoVezzaro's mcp-dominican-layer project, affecting the parse-csv and parse-pdf tools through manipulation of csvUrl and pdfUrl arguments. The vulnerabilities have been disclosed publicly and the vendor has not yet responded.
Disclosed 13 August 2026 · Record updated 13 September 2026
Impact
Server-side request forgery vulnerabilities in CSV and PDF parsing functions allowing remote attacks
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19751
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19752
