CVE-2026-82905

Summary

A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
sdcbchats1.0affected
sdcbchats1.1affected
sdcbchats1.2affected
sdcbchats1.3affected
sdcbchats1.4affected
sdcbchats1.5affected
sdcbchats1.6affected
sdcbchats1.7affected
sdcbchats1.8affected
sdcbchats1.9affected
sdcbchats1.10affected
sdcbchats1.11affected
sdcbchats1.12.0affected

Weaknesses

  • CWE-918: Server-Side Request Forgery

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References