No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 17 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Server. Performing a manipulation of the argument image_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | |
| First Time appeared |
Kira-pgr
Kira-pgr promptshopmcp |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:kira-pgr:promptshopmcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kira-pgr
Kira-pgr promptshopmcp |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-17T10:30:11.394Z
Reserved: 2026-08-17T04:44:22.174Z
Link: CVE-2026-74842
No data.
Status : Received
Published: 2026-08-17T11:16:40.597
Modified: 2026-08-17T11:16:40.597
Link: CVE-2026-74842
No data.
OpenCVE Enrichment
No data.