Description
A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulation of the argument path results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery
Action: Apply Patch
AI Analysis

Impact

A server‑side request forgery flaw exists in the MCP Request Handler of the 021is elvix‑sdk. By manipulating the path argument in the src/mcp/index.ts module, an attacker can compel the server to make HTTP requests to arbitrary destinations, potentially exposing internal resources, exfiltrating data, or leveraging the server as a proxy for other attacks. The vulnerability is categorized as CWE‑918 and can be triggered remotely without local authentication.

Affected Systems

The flaw affects versions of 021is elvix‑sdk up to and including 0.10.1. Systems running these or earlier releases are vulnerable, while later releases are presumed to contain the fix.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates a medium impact that can lead to disclosure of sensitive data or misdirection of network traffic. Exploitation does not require administrative privileges, and the public exploit code is available, meaning attackers can craft malicious requests from the internet. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog, but the remote nature of the attack vector and public exploit warrant prompt attention.

Generated by OpenCVE AI on October 11, 2026 at 08:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade 021is elvix‑sdk to a version newer than 0.10.1 once a vendor patch is released.
  • If an upgrade is not possible, implement network controls to restrict the application from initiating outbound HTTP requests to untrusted hosts, effectively blocking the SSRF path.
  • Monitor outbound traffic for unexpected requests triggered by the application and alert on any anomalies that could indicate exploitation attempts.

Generated by OpenCVE AI on October 11, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulation of the argument path results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title 021is elvix-sdk MCP Request index.ts server-side request forgery
First Time appeared 021is
021is elvix-sdk
Weaknesses CWE-918
CPEs cpe:2.3:a:021is:elvix-sdk:*:*:*:*:*:*:*:*
Vendors & Products 021is
021is elvix-sdk
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T07:15:17.007Z

Reserved: 2026-10-10T13:30:53.462Z

Link: CVE-2026-108542

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T08:16:33.540

Modified: 2026-10-11T08:16:33.540

Link: CVE-2026-108542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T12:23:09Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)