Impact
Based on the description, it is inferred that the attacker can supply crafted URLs as part of a tool call to the web_url_read endpoint. This server‑side request forgery bypass in mcp‑searxng allows the attacker to trick the server into fetching arbitrary internal URLs when the hardened mode is enabled and private URLs are not permitted. The flaw arises because redirect targets are not revalidated, the 0.0.0.0 IP address is not treated as internal, and IPv4‑mapped IPv6 addresses in hexadecimal form are not detected. By supplying such inputs, an attacker‑influenced tool call can cause the MCP server to retrieve content from loopback interfaces, private APIs, internal services, or cloud metadata endpoints, and then forward the content back to the client. This results in the exposure of sensitive data that should remain confined within the internal network. The vulnerability is classified as an information‑disclosure flaw (CWE‑200) and an SSRF (CWE‑918).
Affected Systems
All instances of mcp‑searxng released before version 1.2.0 that have MCP_HTTP_HARDEN turned on and MCP_HTTP_ALLOW_PRIVATE_URLS disabled are affected. The vulnerability was present in the src/url‑reader.ts component of the project maintained by ihor‑sokoliuk.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation detected in the wild is low, yet the existence of the flaw remains a concern for any system that exposes the web_url_read endpoint to untrusted traffic. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation campaigns are reported, but the potential to expose internal data warrants immediate attention. Based on the EPSS score, it is inferred that exploitation in the wild is currently rare, and the likely attack vector involves the web_url_read endpoint, which can be targeted by an attacker supplying a crafted URL.
OpenCVE Enrichment
Github GHSA