{"data":{"id":"c19bcafb-d839-4c91-8ebe-7f3f8558daaa","title":"CVE-2026-65056: mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw","summary":"mcp-webresearch version 0.1.7 has a server-side request forgery vulnerability (SSRF, where a server can be tricked into accessing internal network services it shouldn't). An attacker can use prompt injection (hiding malicious instructions in text sent to the AI) to trick the AI into visiting internal network addresses, allowing the server to expose sensitive information like credentials from cloud metadata services (systems that store configuration and authorization data for cloud instances).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65056","publishedAt":"2026-07-21T21:16:54.287Z","cveId":"CVE-2026-65056","cweIds":["CWE-918"],"cvssScore":"8.2","cvssSeverity":"high","severity":"high","attackType":["prompt_injection","supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["mcp-webresearch"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-21T21:16:54.287Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010","AML.T0051"]}}