CVE-2026-10280
7.3 HIGHA security flaw has been discovered in horizon921 mcpilot 0.1.0
Published: 2026-06-01 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 7.3 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-918
Description
A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP API Call Endpoint. The manipulation of the argument serverBaseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10280
- [Other]https://github.com/horizon921/mcpilot/
- [Other]https://github.com/horizon921/mcpilot/issues/1
- [Other]https://vuldb.com/cve/CVE-2026-10280
- [Other]https://vuldb.com/submit/825426
- [Other]https://vuldb.com/vuln/367573
- [Other]https://vuldb.com/vuln/367573/cti
Related CVEs
Same CWE
- CVE-2026-12210 — A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0 (6.3 MEDIUM)
- CVE-2026-53827 — OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata ... (6.5 MEDIUM)
- CVE-2026-47268 — Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (6.4 MEDIUM)
- CVE-2026-46717 — Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (7.7 HIGH)
- CVE-2026-53607 — ApostropheCMS is an open-source Node.js content management system (3.7 LOW)