CVE-2026-19956Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659. Applying a patch is advised to resolve this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Disclore: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-16); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-16: 3Mentions · 2026-08-17: 1Technical Details · 2026-08-16: 3Technical Details · 2026-08-17: 108-1608-17
Signal classification2 categories
Disclosure
375.0%
Disclore
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-163
Disclore1Disclosure2
2026-08-171
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclore

    CVE-2026-19956 Server-Side Request Forgery in gomarble-ai facebook-ads-mcp-server 0.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19956

    Post summary

    The snippet announces a newly identified SSRF vulnerability (CVE‑2026‑19956) affecting gomarble‑ai facebook‑ads‑mcp‑server 0.1.0, with no evidence of exploitation, PoC, or mitigation.

    00001124
    4.1K followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 17 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🖥️ Go pprof left on a public listener — heap dumps, and the app's own access code, with no login (SiYuan CVE-2026-74799) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: ⚡ MCP code interpreter escaping its sandbox — RCE on the MCP host from one prompt injection (pptr-mcp CVE-2026-19958, Jij-MCP-Server CVE-2026-19964) 📦 WordPress plugin leaking its stored integration credentials to any URL an anonymous visitor names (WooMS CVE-2026-13700) 𝗔𝗱𝗱𝗲𝗱 𝘁𝗼 𝗡𝗲𝘄𝗦𝗰𝗮𝗻 𝗣𝗿𝗼 — 𝗼𝘂𝘁-𝗼𝗳-𝗯𝗮𝗻𝗱: 🔀 MCP tool fetching a caller-supplied URL — internal services and cloud metadata via the agent's own tool call (facebook-ads-mcp-server CVE-2026-19956, graphlit-mcp-server CVE-2026-19957, mcp-florence2 CVE-2026-19984, PromptShopMCP CVE-2026-74842) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #MCP #CSO #REDTEAM

    Post summary

    The tweet provides a daily roundup of newly uncovered CVEs with technical details, functioning as a disclosure of vulnerabilities rather than offering exploits or patches.

    0000067
    5 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19956 A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file https://server.py. Such man… https://www.cve.org/CVERecord?id=CVE-2026-19956 ----- Traducción: CVE-… https://infoflow.cloud`

    Post summary

    The text announces CVE-2026-19956, a vulnerability in gomarble‑ai facebook‑ads‑mcp‑server 0.1.0 affecting the fetch_pagination_url function, with no PoC, exploit, patch, or exploitation details disclosed.

    0000044
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19956 A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file https://server.py. Such man… https://www.cve.org/CVERecord?id=CVE-2026-19956

    Post summary

    A CVE has been disclosed for gomarble‑ai facebook‑ads‑mcp‑server, affecting the fetch_pagination_url function. No exploit, patch, or active exploitation details are provided.

    000001.1K
    58.0K followersView on X

Explore more