Impact
An input validation flaw in the web_url_read endpoint allows an attacker to supply a hostname that resolves to a private, loopback, link‑local, or cloud‑metadata address. Because the server performs DNS resolution after only a lexical hostname check, the attacker can make the server reach internal services, potentially exfiltrating credentials, enumerating hosts, or reading protected data. The flaw does not require authentication in the default HTTP configuration, making it accessible to unauthenticated network clients.
Affected Systems
The vulnerable releases belong to the ihor‑sokoliuk mcp‑searxng project. Any version released before 1.7.1 is affected. Version 1.7.1 and later contain the fix that blocks such untrusted DNS resolutions.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is less than 1% (0.00135), indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the attack vector—unauthenticated network access to an HTTP endpoint—remains feasible. An attacker can leverage the flaw to read internal resources or leak service tokens; the risk is therefore significant for environments where the MCP server is exposed to untrusted networks.
OpenCVE Enrichment