CVE-2026-7146General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-28: 104-2704-28
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-271
General1
2026-04-281
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7146 Server-Side Request Forgery in AlejandroArciniegas mcp-data-vis HTTP Request Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7146

    Post summary

    The entry identifies CVE‑2026‑7146 as a Server‑Side Request Forgery vulnerability in AlejandroArciniegas mcp‑data‑vis HTTP Request Handler, but provides no PoC, exploit, active usage, patch, or debunking details.

    0000054
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7146 A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the fun… https://www.cve.org/CVERecord?id=CVE-2026-7146

    Post summary

    A CVE-2026-7146 vulnerability has been detected for AlejandroArciniegas mcp-data-vis, but the post offers no further technical details, patch information, or evidence of exploitation.

    0000052
    57.3K followersView on X

Explore more