No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-27T19:30:13.300Z
Reserved: 2026-04-26T19:58:59.072Z
Link: CVE-2026-7147
Updated: 2026-04-27T19:30:08.927Z
Status : Deferred
Published: 2026-04-27T19:16:53.663
Modified: 2026-04-27T19:25:04.600
Link: CVE-2026-7147
No data.
OpenCVE Enrichment
No data.