Alibaba Cloud · Alibabacloud-Dataworks-Mcp-Server · CVE-2026-19339
**Name of the Vulnerable Software and Affected Versions**
aliyun alibabacloud-dataworks-mcp-server versions prior to 1.0.44
**Description**
A security flaw allows remote attackers to perform server-side request forgery (SSRF), a technique where an attacker induces a server to make requests to an unintended location. The issue exists in the `ReadResourceRequestSchema()` function within the `src/resources/initResources.ts` file, triggered by the manipulation of the `request.params.uri` variable.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to or avoid using the `ReadResourceRequestSchema()` function.