Impact
A server‑side request forgery flaw exists in the MCP Request Handler of the 021is elvix‑sdk. By manipulating the path argument in the src/mcp/index.ts module, an attacker can compel the server to make HTTP requests to arbitrary destinations, potentially exposing internal resources, exfiltrating data, or leveraging the server as a proxy for other attacks. The vulnerability is categorized as CWE‑918 and can be triggered remotely without local authentication.
Affected Systems
The flaw affects versions of 021is elvix‑sdk up to and including 0.10.1. Systems running these or earlier releases are vulnerable, while later releases are presumed to contain the fix.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates a medium impact that can lead to disclosure of sensitive data or misdirection of network traffic. Exploitation does not require administrative privileges, and the public exploit code is available, meaning attackers can craft malicious requests from the internet. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog, but the remote nature of the attack vector and public exploit warrant prompt attention.
OpenCVE Enrichment