Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_url

Identifier
CVE-2026-108583
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

zotero-mcp versions 0.10.0 through 0.14.1 contain a server-side request forgery flaw in _fetch_embedded_metadata, which fetches URLs without destination validation. An attacker who uses prompt injection to make the agent call zotero_add_by_url can reach loopback, private, or link-local hosts, directly or through redirects, and leak citation meta-tags and error details.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.