Impact
The vulnerability is in the fetch_pagination_url function of server.py, allowing an attacker to craft requests that cause the server to retrieve resources from arbitrary URLs. This can enable the attacker to target internal network services, perform reconnaissance, or exfiltrate sensitive data. The flaw compromises confidentiality and integrity of any internal resources accessible from the server, while also potentially creating a foothold for further internal attacks.
Affected Systems
gomarble‑ai facebook‑ads‑mcp‑server version 0.1.0 is affected. No other affected versions or vendor products are listed.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity SSRF. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, and the vulnerability can be exploited without local access. Because the patch is available, the risk can be mitigated by applying the update.
OpenCVE Enrichment