Threat · curated 14 Aug 2026
CVE-2026-19339 in alibabacloud-dataworks-mcp-server
First reported vuldb.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-19339 affects a Model Context Protocol server, meaning an unauthenticated remote attacker could abuse the MCP resource-fetching path to reach internal networks or restricted systems and pivot within cloud data pipelines.
CVE-2026-19339 is a server-side request forgery flaw in aliyun alibabacloud-dataworks-mcp-server up to version 1.0.43, where the ReadResourceRequestSchema function in src/resources/initResources.ts fails to validate the request.params.uri argument. The flaw is remotely exploitable without authentication (CWE-918), and the project maintainers had not responded to the initial issue report at time of disclosure.