# Positive fixture for CVE-2026-19984: get_images SSRF via the `src` argument.
# Upstream ships no code fix, so every published version is exposed and the pin is
# presence-only — 0.3.13 is the latest release, not a safe one.
mcp-florence2==0.3.13
