Impact
The vulnerability exists in an unknown function within dcrClients.ts of MissionSquad mcp-api. It allows an attacker to abuse a server‑side request forgery (SSRF) flaw, enabling the remote execution of arbitrary outbound requests from the server. The flaw is categorized as CWE-918 and can be triggered from remote without special credentials.
Affected Systems
Affected deployments run MissionSquad mcp‑api up to and including version 1.11.9. The patch noted as f068ab4ad6f0907ac7001b995588c2673f11a755 was released in version 1.11.10, removing the vulnerable function. All other versions after 1.11.10 are considered safe.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, though the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and does not require authentication according to the description. While the potential for internal network reconnaissance or service discovery exists, the lack of additional details makes exploitation effort moderate.
OpenCVE Enrichment