PT-2026-73203 · Pypi · Mcp-Florence2

·

CVE-2026-19984

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jkawamoto mcp-florence2 versions prior to 0.3.14
Description A flaw in the get images() function within the src/mcp florence2/ init .py file allows for server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. This occurs through the manipulation of the src argument and can be initiated remotely.
Recommendations Route all HTTP(S) requests through an SSRF-safe proxy server to mitigate the risk.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19984

Affected Products

Mcp-Florence2