MediumVulnerabilityLLM-specific
CVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_url
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108583
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
zotero-mcp versions 0.10.0 through 0.14.1 contain a server-side request forgery flaw in _fetch_embedded_metadata, which fetches URLs without destination validation. An attacker who uses prompt injection to make the agent call zotero_add_by_url can reach loopback, private, or link-local hosts, directly or through redirects, and leak citation meta-tags and error details.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSimilar attack · Dark Reading
- MediumGHSA-4xxv-6wmf-xf45: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspaceSimilar attack · GitHub Advisory Database