PT-2026-73171 · Gomarble Ai · Facebook-Ads-Mcp-Server

·

CVE-2026-19956

·

Published

2026-08-16

·

Updated

2026-08-16

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gomarble-ai facebook-ads-mcp-server version 0.1.0
Description A remote attacker can perform server-side request forgery (SSRF), a technique where the server is coerced into making unauthorized requests to internal or external resources, by manipulating the fetch pagination url() function within the server.py file.
Recommendations Apply patch 4e53875aa22e8991c2fa4a7660d86e1caba66659 for version 0.1.0. As a temporary workaround, restrict the use of the fetch pagination url() function until the patch is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19956

Affected Products

Facebook-Ads-Mcp-Server