PT-2026-45450 · Indrasishbanerjee · Aem-Mcp-Server

·

CVE-2026-10274

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions indrasishbanerjee aem-mcp-server versions up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583
Description A server-side request forgery (SSRF) issue exists within the Axios Request Flow component. This occurs when the getAssetMetadata() function in the src/mcp-server.ts file fails to properly handle the assetPath argument, allowing a remote attacker to manipulate the request. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations As a temporary workaround, restrict the use of the assetPath argument within the getAssetMetadata() function to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10274

Affected Products

Aem-Mcp-Server