Impact
The vulnerability resides in the parse-pdf function of EnzoVezzaro mcp-dominican-layer. By manipulating the pdfUrl argument, an attacker can cause the server to issue an HTTP request to an arbitrary URL. This enables the attacker to reach internal resources or misdirect traffic, compromising confidentiality and integrity of the system’s communication channels. The vulnerability allows remote exploitation, and an exploit has already been made public.
Affected Systems
Any deployment of EnzoVezzaro mcp-dominican-layer that includes the parse-pdf component prior to the commit 39dd373786712650097ad31db27d5c477c8f9c82 is at risk. No specific version numbers are listed, so all versions up to and including that commit are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, with no EPSS value available and the CVE not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the public nature of the exploit and the ability to initiate the attack remotely mean that the risk remains real. The most likely attack vector is a web or API request that passes a user-supplied PDF URL to the vulnerable function.
OpenCVE Enrichment