Impact
A server‑side request forgery flaw exists in the mastergo‑magic‑mcp library. By manipulating the URL argument provided to the z.string function in src/tools/get-component-link.ts, an attacker can cause the server to perform arbitrary HTTP requests to any destination, potentially exposing internal services or facilitating further attacks. This vulnerability is classified as CWE‑918.
Affected Systems
The flaw affects the mastergo‑magic‑mcp component of mastergo‑design, in all releases up to and including version 0.2.0. The vulnerable code resides in the mcp__getComponentLink component, specifically in the get‑component‑link.ts source file.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact level, while the EPSS score of less than 1 % shows a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. However, the fact that an exploit has been publicly shared and can be launched remotely means that any installation exposed to the public network remains at tangible risk for attackers to instruct the server to reach internal or private resources.
OpenCVE Enrichment