A vulnerability, which was classified as critical, was found in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery.

This vulnerability is handled as CVE-2026-19373. It is possible to launch the attack on the local host. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.