Description
mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enabled and MCP_HTTP_ALLOW_PRIVATE_URLS is not enabled because redirect targets are not revalidated, 0.0.0.0 is not classified as an internal address, and IPv4-mapped IPv6 literals canonicalized to hexadecimal form are not recognized. These inputs allow an attacker-influenced tool call to make the MCP server fetch loopback or internal HTTP resources and return content from local services, private APIs, service-mesh endpoints, or cloud metadata endpoints. The separate hostname-to-private-address case addressed by the earlier partial fix is not part of these residual bypasses. This issue is fixed in version 1.2.0.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Based on the description, it is inferred that the attacker can supply crafted URLs as part of a tool call to the web_url_read endpoint. This server‑side request forgery bypass in mcp‑searxng allows the attacker to trick the server into fetching arbitrary internal URLs when the hardened mode is enabled and private URLs are not permitted. The flaw arises because redirect targets are not revalidated, the 0.0.0.0 IP address is not treated as internal, and IPv4‑mapped IPv6 addresses in hexadecimal form are not detected. By supplying such inputs, an attacker‑influenced tool call can cause the MCP server to retrieve content from loopback interfaces, private APIs, internal services, or cloud metadata endpoints, and then forward the content back to the client. This results in the exposure of sensitive data that should remain confined within the internal network. The vulnerability is classified as an information‑disclosure flaw (CWE‑200) and an SSRF (CWE‑918).

Affected Systems

All instances of mcp‑searxng released before version 1.2.0 that have MCP_HTTP_HARDEN turned on and MCP_HTTP_ALLOW_PRIVATE_URLS disabled are affected. The vulnerability was present in the src/url‑reader.ts component of the project maintained by ihor‑sokoliuk.

Risk and Exploitability

The CVSS base score of 6.3 indicates moderate severity. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation detected in the wild is low, yet the existence of the flaw remains a concern for any system that exposes the web_url_read endpoint to untrusted traffic. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation campaigns are reported, but the potential to expose internal data warrants immediate attention. Based on the EPSS score, it is inferred that exploitation in the wild is currently rare, and the likely attack vector involves the web_url_read endpoint, which can be targeted by an attacker supplying a crafted URL.

Generated by OpenCVE AI on September 20, 2026 at 14:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 1.2.0 or later, which contains the fix for the SSRF bypass.
  • Until the upgrade can be performed, enable the MCP_HTTP_ALLOW_PRIVATE_URLS setting to block internal URL access.
  • Restrict access to the web_url_read endpoint to trusted clients only or implement firewall rules that deny outbound connections to internal IP ranges.

Generated by OpenCVE AI on September 20, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wppf-h75h-6pm6 SearXNG MCP Server: Additional hardened-mode SSRF bypasses
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ihor-sokoliuk
Ihor-sokoliuk mcp-searxng
Vendors & Products Ihor-sokoliuk
Ihor-sokoliuk mcp-searxng

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enabled and MCP_HTTP_ALLOW_PRIVATE_URLS is not enabled because redirect targets are not revalidated, 0.0.0.0 is not classified as an internal address, and IPv4-mapped IPv6 literals canonicalized to hexadecimal form are not recognized. These inputs allow an attacker-influenced tool call to make the MCP server fetch loopback or internal HTTP resources and return content from local services, private APIs, service-mesh endpoints, or cloud metadata endpoints. The separate hostname-to-private-address case addressed by the earlier partial fix is not part of these residual bypasses. This issue is fixed in version 1.2.0.
Title mcp-searxng hardened-mode SSRF bypasses permit internal URL access
Weaknesses CWE-200
CWE-918
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Ihor-sokoliuk Mcp-searxng
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:39:46.212Z

Reserved: 2026-06-15T22:53:58.562Z

Link: CVE-2026-54689

cve-icon Vulnrichment

Updated: 2026-09-17T16:39:38.360Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:23.477

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-918

    Server-Side Request Forgery (SSRF)