Description
mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllowed() in src/url-reader.ts runs only when MCP_HTTP_HARDEN is enabled, even though MCP_HTTP_HARDEN is disabled by default in src/http-security.ts. In the default configuration, an attacker who influences the URL selected by a user or AI agent can make the server fetch loopback, private-network, or cloud metadata endpoint resources and return their contents into the model context. file:// URLs remain rejected, and the separate DNS-resolution and redirect-validation bypasses are outside this record. This issue is fixed in version 1.2.0.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server Side Request Forgery exposing internal network and cloud metadata resources
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when the service’s web_url_read endpoint forwards a caller‑supplied URL to its internal fetch mechanism without enforcing URL validation, because the guard assertUrlAllowed() is only invoked when the management configuration flag MCP_HTTP_HARDEN is set. As MCP_HTTP_HARDEN is disabled by default in the released software, an attacker who can dictate the URL used by the AI assistant or another user can cause the server to retrieve arbitrary resources from internal network addresses, localhost, or cloud metadata endpoints. The retrieved data is then injected into the model’s context, effectively leaking sensitive internal information. This flaw is classified as CWE-918 and has a CVSS score of 6.5.

Affected Systems

All installations of the mcp‑searxng Model Context Protocol server running a version earlier than 1.2.0 are affected when the MCP_HTTP_HARDEN setting is left at its default value, which is assistant or user input source, as long as the supplied URL passes through web_url_read.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity. EPSS data indicates a score of less than 1%, showing a low probability of exploitation, and the issue has not been listed in CISA KEV. Exploitation requires the ability to influence the URL that the model calls, which can be achieved via normal user interaction or by altering the server may retrieve internal secrets, configuration files or cloud service metadata, granting an attacker a foothold to further compromise the environment.

Generated by OpenCVE AI on September 20, 2026 at 14:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mcp-searxng to version 1.2.0 or later, which re‑enables URL validation.
  • If an upgrade cannot occur immediately, modify the configuration to enable MCP_HTTP_HARDEN so the internal‑address guard becomes active.
  • Limit or validate the URLs that users or AI agents can request, for or domains.

Generated by OpenCVE AI on September 20, 2026 at 14:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q87f-qc2r-2gw4 SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ihor-sokoliuk
Ihor-sokoliuk mcp-searxng
Vendors & Products Ihor-sokoliuk
Ihor-sokoliuk mcp-searxng

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllowed() in src/url-reader.ts runs only when MCP_HTTP_HARDEN is enabled, even though MCP_HTTP_HARDEN is disabled by default in src/http-security.ts. In the default configuration, an attacker who influences the URL selected by a user or AI agent can make the server fetch loopback, private-network, or cloud metadata endpoint resources and return their contents into the model context. file:// URLs remain rejected, and the separate DNS-resolution and redirect-validation bypasses are outside this record. This issue is fixed in version 1.2.0.
Title mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Ihor-sokoliuk Mcp-searxng
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:01:31.029Z

Reserved: 2026-06-15T22:53:58.561Z

Link: CVE-2026-54688

cve-icon Vulnrichment

Updated: 2026-09-15T19:01:27.550Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:23.333

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)