Description
A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Server‑Side Request Forgery vulnerability exists in NocteDefensor LudusMCP 1.0.24. The issue arises from the read_range_config component, where manipulation of the ‘Source’ argument allows an attacker to cause the server to unknowingly make HTTP requests to arbitrary URLs. This flaw can be exploited remotely and may enable an attacker to access internal network resources, request sensitive data, or interact with other services on behalf of the vulnerable host.

Affected Systems

The affected product is NocteDefensor LudusMCP version 1.0.24. The vulnerability is tied to the src/tools/rangeConfig.ts file of the read_range_config functionality, which appears to be a component for managing configuration ranges. No other products or versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 places this flaw in the moderate risk range, indicating a significant but not critical threat. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation. Attackers could leverage the SSRF to reach internal services if the vulnerable host is connected to an internal network, but the lack of a public patch and the vendor’s unresponsive stance increase uncertainty about remediation options.

Generated by OpenCVE AI on August 9, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the project’s issue tracker for any new patches or updates from NocteDefensor and plan to upgrade to a patched version once available.
  • Restrict the outbound network access of the server running LudusMCP to a closed list of legitimate destinations, thereby limiting the impact of any SSRF attempts.
  • Deploy a Web‑Application Firewall or equivalent filtering mechanism to detect and block suspicious outbound requests that may indicate SSRF activity.

Generated by OpenCVE AI on August 9, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title NocteDefensor LudusMCP read_range_config rangeConfig.ts server-side request forgery
First Time appeared Noctedefensor
Noctedefensor ludusmcp
Weaknesses CWE-918
CPEs cpe:2.3:a:noctedefensor:ludusmcp:*:*:*:*:*:*:*:*
Vendors & Products Noctedefensor
Noctedefensor ludusmcp
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Noctedefensor Ludusmcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-10T16:27:01.759Z

Reserved: 2026-08-09T06:04:35.055Z

Link: CVE-2026-19367

cve-icon Vulnrichment

Updated: 2026-08-10T16:26:49.596Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T20:16:40.007

Modified: 2026-08-12T20:59:21.023

Link: CVE-2026-19367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T22:00:10Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)