CVE-2026-19340: Server-Side Request Forgery Vulnerability in ProjectHub-Mcp
A server-side request forgery (SSRF) vulnerability has been identified in ProjectHub-Mcp up to version 5.0.0. The vulnerability, tracked as CVE-2026-19340, has a CVSS score of 6.3 and allows remote attackers to manipulate the URL argument in the Webhooks API, potentially leading to unauthorized access and data breaches. The project vendor, anubissbe, has been informed but has not yet responded. Organizations using affected versions should apply patches or workarounds immediately.