Impact
A Server‑Side Request Forgery vulnerability exists in NocteDefensor LudusMCP 1.0.24. The issue arises from the read_range_config component, where manipulation of the ‘Source’ argument allows an attacker to cause the server to unknowingly make HTTP requests to arbitrary URLs. This flaw can be exploited remotely and may enable an attacker to access internal network resources, request sensitive data, or interact with other services on behalf of the vulnerable host.
Affected Systems
The affected product is NocteDefensor LudusMCP version 1.0.24. The vulnerability is tied to the src/tools/rangeConfig.ts file of the read_range_config functionality, which appears to be a component for managing configuration ranges. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 places this flaw in the moderate risk range, indicating a significant but not critical threat. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation. Attackers could leverage the SSRF to reach internal services if the vulnerable host is connected to an internal network, but the lack of a public patch and the vendor’s unresponsive stance increase uncertainty about remediation options.
OpenCVE Enrichment