CVE-2026-7147: A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Perfor...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.3.
A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remot...
Required action: Review and patch if applicable to your AI infrastructure.