Impact
mcp-webresearch 0.1.7 allows an attacker to execute a server‑side request forgery by exploiting a missing internal IP filtering check when the visit_page tool processes URLs. The flaw is a CWE‑918 vulnerability that permits injection of URLs referencing loopback, link‑local or cloud metadata addresses, causing the Playwright browser on the server to fetch sensitive internal endpoints. The returned content, which may include credentials or other confidential data, is then injected into the LLM’s context, potentially leaking information to an attacker.
Affected Systems
The affected product is mzxrai’s mcp-webresearch component, version 0.1.7. No other affected versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.3 classifies the weakness as high severity, while an EPSS score of less than 1 % indicates a very low current probability of exploitation. The vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring the attacker to supply malicious input through the LLM prompt that is subsequently used by visit_page. Successful exploitation would allow reading of internal network resources and the leakage of sensitive data into the model context.
OpenCVE Enrichment