Impact
The vulnerability arises when the service’s web_url_read endpoint forwards a caller‑supplied URL to its internal fetch mechanism without enforcing URL validation, because the guard assertUrlAllowed() is only invoked when the management configuration flag MCP_HTTP_HARDEN is set. As MCP_HTTP_HARDEN is disabled by default in the released software, an attacker who can dictate the URL used by the AI assistant or another user can cause the server to retrieve arbitrary resources from internal network addresses, localhost, or cloud metadata endpoints. The retrieved data is then injected into the model’s context, effectively leaking sensitive internal information. This flaw is classified as CWE-918 and has a CVSS score of 6.5.
Affected Systems
All installations of the mcp‑searxng Model Context Protocol server running a version earlier than 1.2.0 are affected when the MCP_HTTP_HARDEN setting is left at its default value, which is assistant or user input source, as long as the supplied URL passes through web_url_read.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. EPSS data indicates a score of less than 1%, showing a low probability of exploitation, and the issue has not been listed in CISA KEV. Exploitation requires the ability to influence the URL that the model calls, which can be achieved via normal user interaction or by altering the server may retrieve internal secrets, configuration files or cloud service metadata, granting an attacker a foothold to further compromise the environment.
OpenCVE Enrichment
Github GHSA