CVE-2026-65056: mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw
Summary
mcp-webresearch version 0.1.7 has a server-side request forgery vulnerability (SSRF, where a server can be tricked into accessing internal network services it shouldn't). An attacker can use prompt injection (hiding malicious instructions in text sent to the AI) to trick the AI into visiting internal network addresses, allowing the server to expose sensitive information like credentials from cloud metadata services (systems that store configuration and authorization data for cloud instances).
Vulnerability Details
8.2(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
network
low
none
required
July 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65056
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 92%