Security Patch & Exposure

CVE-2026-19367: SSRF Risk in NocteDefensor LudusMCP

CVE-2026-19367 describes a remotely exploitable server-side request forgery vulnerability in NocteDefensor LudusMCP 1.0.24. The issue affects the read_range_config component and involves the Source argument in src/tools/rangeConfig.ts. Organizations should verify exposure, restrict outbound requests, validate input, and monitor official advisories for remediation details.

CVE-2026-19367 describes a remotely exploitable server-side request forgery vulnerability in NocteDefensor LudusMCP 1.0.24. The issue affects the read_range_config component and involves the Source argument in src/tools/rangeConfig.ts. Organizations should verify exposure, restrict outbound requests, validate input, and monitor official advisories for remediation details.

What does CVE-2026-19367 affect?

According to the supplied CVEfeed.io entry, CVE-2026-19367 affects NocteDefensor LudusMCP 1.0.24. The reported vulnerable functionality is read_range_config in src/tools/rangeConfig.ts.

What vulnerability does the record describe?

The record identifies server-side request forgery, or SSRF. Manipulation of the Source argument may cause the server to make unintended requests to external resources. The supplied record states that exploitation may occur remotely.

How severe is the reported issue?

The supplied record lists differing severity assessments: CVSS 2.0 score 6.5, CVSS 3.1 score 6.3, and CVSS 4.0 score 2.1. These values use different scoring systems and should not be combined. The record labels the CVSS 2.0 and CVSS 3.1 results as medium and the CVSS 4.0 result as low.

What should defenders verify?

  • Whether NocteDefensor LudusMCP 1.0.24 is deployed.

  • Whether the read_range_config functionality is enabled or reachable.

  • Whether user-controlled values can influence the Source argument.

  • Whether application servers can reach internal or sensitive network resources.

  • Whether outbound request logs show unexpected destinations or protocols.

What mitigations does the supplied record recommend?

The supplied record recommends validating and sanitizing user input, validating external resource requests, restricting allowed domains, and updating affected software. It does not provide a confirmed fixed version or vendor remediation statement.

What evidence remains incomplete?

The supplied source does not confirm a patched release, exploit availability, affected version range beyond the stated product version, or detailed attack prerequisites. The record also states that the project had not responded when the entry was published. Treat remediation status as provisional until confirmed through official project or vulnerability-management sources.

FAQ operasional

Pertanyaan lanjutan untuk tim IT.

Apa langkah pertama setelah membaca CVE-2026-19367: SSRF Risk in NocteDefensor LudusMCP?

Mulai dari inventaris sistem yang terdampak, owner operasional, kontrol yang sudah berjalan, dan bukti terakhir seperti patch status, log, atau hasil restore test.

Tim mana yang sebaiknya dilibatkan?

Libatkan IT manager, security atau infrastructure owner, application owner, dan pihak operasional yang memahami dampak bisnis jika sistem harus dipatch, diisolasi, atau dipulihkan.

Kapan perlu eskalasi ke assessment myBATICloud?

Eskalasi jika sistem bersifat kritikal, terekspos internet, akses admin belum rapi, backup belum pernah diuji, atau tim membutuhkan prioritas teknis yang bisa dieksekusi dalam 30 hari.