Impact
The vulnerability is a server‑side request forgery in the loadSource function of swagger-parser.ts within the fetch_swagger component. An attacker can remotely trigger the component to request arbitrary URLs, potentially accessing internal resources or exfiltrating data. The flaw is classified as CWE‑918 and carries a CVSS score of 5.3, indicating moderate severity.
Affected Systems
This issue affects the eyaushev swagger‑testcase‑mcp project. Versions of the project that contain the commit 5babb27c951fb404bc2b25ec80593616e49054e5 are vulnerable, and because the project follows a rolling release model no specific version numbers can be listed. Any deployment that includes this module without a subsequent fix is at risk.
Risk and Exploitability
The flaw can be exploited remotely and the exploit code has already been released to the public. While the EPSS score is not available, the lack of a KEV listing and the CVSS of 5.3 suggest moderate risk. Attackers can leverage the server‑side request forgery to reach internal services and potentially compromise confidentiality or integrity of data accessed through the vulnerable component.
OpenCVE Enrichment