CVE-2026-5832Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Technical Details · 2026-04-09: 204-0904-10
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure2General1
2026-04-101
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5832 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5832 #CVE-2026-5832 #CVE #High #CyberSecurity #InfoSec https://t.co/qmINLgUqvC

    Post summary

    The tweet announces the CVE with basic severity info but provides no technical or operational details, so it is classified as a general notice.

    0000034
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5832 A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src… https://www.cve.org/CVERecord?id=CVE-2026-5832 ----- Traducción: CVE-2026-5832 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5832, notes a weakness in atototo api-lab-mcp up to version 0.2.1 affecting a specific function, but supplies no further technical, exploit, or patch information.

    0000033
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5832 A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src… https://www.cve.org/CVERecord?id=CVE-2026-5832

    Post summary

    A weakness in atototo api‑lab‑mcp (up to version 0.2.1) has been disclosed, affecting a specific function within the code.

    00000290
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5832 Server-Side Request Forgery in atototo api-lab-mcp HTTP Interface Up to 0.2.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5832

    Post summary

    The snippet provides a disclositional update about a Server‑Side Request Forgery vulnerability affecting atototo api‑lab‑mcp up to version 0.2.1, without any PoC, exploit, or mitigation details.

    0000054
    4.0K followersView on X

Explore more