Impact
The vulnerability resides in the add_attachment_from_public_url function of KS‑GEN‑AI jira‑mcp‑server, where an attacker can manipulate the imageUrl parameter to invoke axios.get with an arbitrary URL, causing the server to perform a request on the attacker's behalf. This server‑side request forgery (CWE‑918) can expose internal resources or outwardly reach external services and may be leveraged to probe internal networks or exfiltrate data. The CVSS score of 4.8 reflects that while the flaw is present, it does not grant complete system compromise but still allows unauthorized outbound traffic.
Affected Systems
Affected is KS‑GEN‑AI jira‑mcp‑server version 0.2.0. No other vendors or versions are listed; the manufacturer is the sole vendor. The CVE does not specify further sub‑components or edition details.
Risk and Exploitability
The flaw is classified as a local attack; the attacker needs a path to the server, but the exploitation can lead to internal network reconnaissance and potentially further compromise. The EPSS score is unavailable; the vulnerability is not listed in the government KEV catalog, which suggests limited exploitation data but does not negate the risk. Given the SSRF nature and the need for local access, the threat is moderate; an organization whose server is exposed to untrusted inputs should consider this a potential entry point for internal scans or data leakage.
OpenCVE Enrichment