Impact
EnzoVezzaro mcp-dominican-layer contains an SSRF flaw in the axios.get call used by the parse‑csv tool. An attacker can supply an arbitrary csvUrl value, causing the vulnerable component to perform a server‑side HTTP request to any address. This can lead to disclosure of internal network services, credential exposure, or further exploitation of internal systems. The weakness falls under CWE‑918 and is available for exploitation as public proof‑of‑concept code is published.
Affected Systems
The vulnerability affects all versions of the EnzoVezzaro mcp‑dominican‑layer package up to commit 39dd373786712650097ad31db27d5c477c8f9c82. The project follows a rolling‑release model and no fixed version has been released yet. No patch has been applied by the maintainers and the issue remains reported but unattended.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV database, but exploit code has already been published, demonstrating real‑world use. Attackers can trigger the flaw remotely by shaping a crafted csvUrl and invoking the parse‑csv tool, implying that any exposed endpoint that uses this component is a potential entry point.
OpenCVE Enrichment