Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Open-WebSearch: SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
Vulnerability Description
Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Open-WebSearch 代码问题漏洞
Vulnerability Description
Open-WebSearch是Aasee个人开发者的一个无需API密钥的多引擎网页搜索与内容获取工具。 Open-WebSearch 2.1.7之前版本存在代码问题漏洞,该漏洞源于URL安全检查未识别IPv6字面量且未解析DNS,可能导致非盲目SSRF。
CVSS Information
N/A
Vulnerability Type
N/A