Impact
A flaw in get_images of mcp‑florence2 allows an attacker to supply a crafted src argument that causes the server to make arbitrary outbound HTTP(S) requests. The vulnerability is a classic SSRF (CWE‑918) that could expose internal resources or exfiltrate data. The code change can be triggered remotely and an exploit is publicly available, meaning the data could be accessed by unauthenticated actors if the application makes requests to sensitive internal endpoints or exposes internal services.
Affected Systems
The issue exists in the jkawamoto mcp‑florence2 package up to version 0.3.13. All installations of this package below that version are potentially vulnerable; upgrades to a later release that removes the flaw are recommended.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability represents moderate risk. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack can be performed over the network without authentication, and the publicly released exploit demonstrates that malicious parties can redirect the server to arbitrary targets. If the target network contains critical internal services, the impact could include data disclosure or further lateral movement.
OpenCVE Enrichment