CYBERHAWK / CVE / CVE-2026-7158

CVE-2026-7158

mcp-url-downloader

HIGH CVSS 7.3 ai

The flaw

Server-side request forgery vulnerability in URL validation function allows remote exploitation.

What to do

Update to latest version or patch vulnerability in _validate_url_safe function

▸ Scan my repo for CVE-2026-7158

References

First seen 2026-05-01 · Tracked by PickBits CyberHawk · Weekly CVE digest