Threat · curated 14 Aug 2026

CVE-2026-19339 in alibabacloud-dataworks-mcp-server

Coverage timeline

8 Aug 2026vuldb.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-19339 affects a Model Context Protocol server, meaning an unauthenticated remote attacker could abuse the MCP resource-fetching path to reach internal networks or restricted systems and pivot within cloud data pipelines.

CVE-2026-19339 is a server-side request forgery flaw in aliyun alibabacloud-dataworks-mcp-server up to version 1.0.43, where the ReadResourceRequestSchema function in src/resources/initResources.ts fails to validate the request.params.uri argument. The flaw is remotely exploitable without authentication (CWE-918), and the project maintainers had not responded to the initial issue report at time of disclosure.