Impact
A weakness was discovered in the makeRequest function of the BaseConfigSchema component in PhialsBasement’s KoboldCPP-MCP-Server version 1.0.0. By manipulating the apiUrl argument, an attacker can force the server to perform arbitrary HTTP requests, a classic server‑side request forgery (CWE‑918). The exploit can be executed on the localhost, allowing a local attacker to reach internal services or external resources that the server should not access. The primary impact is the potential compromise of data confidentiality or integrity through unauthorized network requests; it does not provide remote code execution.
Affected Systems
The product affected is PhialsBasement’s KoboldCPP-MCP-Server, version 1.0.0. No other versions are listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS base score is 4.8, indicating a moderate severity and an attack vector limited to the local host. EPSS information is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploitation. The attacker must have some local access to trigger the vulnerable function; remote exploitation is not documented. Overall risk remains moderate, but organizations should evaluate the potential impact of internal‑outbound requests in their environment.
OpenCVE Enrichment