Impact
A weakness was discovered in the Webhooks API of anubissbe ProjectHub‑Mcp that allows an attacker to manipulate the URL argument in the backend-fix/complete_backend.js file, leading to a server‑side request forgery (SSRF). This flaw permits a remote actor to trigger internal HTTP requests from the affected server, potentially exposing internal resources, exfiltrating data, or pivoting within a network. The vulnerability is classified as a moderate severity issue with a CVSS score of 5.3, and it does not compromise code execution but can be used for malicious outbound communications.
Affected Systems
The problem exists in all versions of anubissbe ProjectHub‑Mcp up to and including 5.0.0. Any deployment of this product that includes the Webhooks API component is affected; the specific file impacted is backend-fix/complete_backend.js. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS score signals a medium risk and the AE probability is unknown as EPSS data is not available. The flaw is not listed in the CISA KEV catalog. Attackers can exploit this vulnerability remotely by sending a crafted request to the Webhooks API that contains a malicious URL parameter; no local privilege or advanced access prerequisites are documented. The impact is limited to the server's outbound network interactions but can lead to compromise of internal services.
OpenCVE Enrichment