{"data":{"id":"54e80af3-9874-48c8-bae4-7d40f59fca49","title":"GHSA-q87f-qc2r-2gw4: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)","summary":"SearXNG MCP Server has an SSRF vulnerability (server-side request forgery, where a server is tricked into fetching URLs chosen by an attacker) in its web_url_read tool because the internal-address guard is disabled by default. An attacker who can control the URL input (for example, through prompt injection, where hidden instructions in AI input trick the model into producing malicious content) can make the server fetch private internal services or cloud metadata and return their contents, but this only happens when the MCP_HTTP_HARDEN setting is off by default.","solution":"The source text describes the desired remediation but does not provide a concrete patch or version fix. The recommended approach stated is: 'Enable the internal-address filtering by default (fail safe): make assertUrlAllowed run unconditionally and require an explicit opt-out only for trusted environments. Strengthen the check to resolve the host and reject loopback, link-local/metadata (169.254.0.0/16), 0.0.0.0/8, and private ranges, and re-validate on every redirect hop (or pin to the validated IP).' No patched version is mentioned in the source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-q87f-qc2r-2gw4","publishedAt":"2026-08-19T19:23:08.000Z","cveId":"CVE-2026-54688","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["rag_poisoning"],"issueType":"vulnerability","affectedPackages":["mcp-searxng@< 1.2.1 (fixed: 1.2.1)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["SearXNG MCP Server","Model Context Protocol (MCP)"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-19T19:23:08.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}