PT-2026-73203 · Pypi · Mcp-Florence2
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
jkawamoto mcp-florence2 versions prior to 0.3.14
Description
A flaw in the
get images() function within the src/mcp florence2/ init .py file allows for server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. This occurs through the manipulation of the src argument and can be initiated remotely.Recommendations
Route all HTTP(S) requests through an SSRF-safe proxy server to mitigate the risk.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Florence2