{"data":{"id":"ebbb473d-eaf3-477d-a0f2-c1d00998dc84","title":"GHSA-wppf-h75h-6pm6: SearXNG MCP Server: Additional hardened-mode SSRF bypasses","summary":"The mcp-searxng server has a feature in hardened mode that tries to prevent SSRF (server-side request forgery, where an attacker tricks a server into fetching URLs it shouldn't) attacks on the web_url_read function. However, three bypasses still exist: redirects from allowed URLs to internal addresses aren't re-checked, the address 0.0.0.0 isn't blocked as internal, and IPv6-mapped IPv4 addresses can bypass checks after the URL parser converts them to a different format.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-wppf-h75h-6pm6","publishedAt":"2026-08-19T19:23:16.000Z","cveId":"CVE-2026-54689","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["rag_poisoning"],"issueType":"vulnerability","affectedPackages":["mcp-searxng@< 1.2.1 (fixed: 1.2.1)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["mcp-searxng","Model Context Protocol"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-19T19:23:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}