A vulnerability was found in dmitriiweb article-scraper-mcp 1.0.0 and classified as critical. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery.

This vulnerability was named CVE-2026-19375. The attack may be performed from remote. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.