CVE-2026-5323: A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipulation results in server-side request forgery. T...
Added to the CISA Known Exploited Vulnerabilities catalog on 02 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.3.
A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipulation results in server-side request forgery. The attack must be initiated from a local position. The exploit has been made public and could be use...
Required action: Review and patch if applicable to your AI infrastructure.