mcp-searxng 是一个模型上下文协议(MCP)服务器,它通过 SearXNG 为 AI 助手提供网络搜索和 URL 读取功能。在 1.2.0 之前, 功能会将调用方提供的 URL 直接传入服务端的 fetch 路径,而 中的 检查仅在启用 时才会执行,但 中 默认是禁用的。在默认配置下,如果攻击者能够影响用户或 AI 代理所选的 URL,就可以让服务器获取环回地址(loopback)、私有网络或云元数据端点(cloud metadata endpoint)的资源,并将其内容返回到模型上下文中。 URL 仍然
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ihor-sokoliuk | mcp-searxng | < 1.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ihor-sokoliuk | mcp-searxng | < 1.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58483 | 7.5 HIGH | mcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` |
| CVE-2026-58485 | 7.1 HIGH | mcp-searxng: DNS-resolved Private Hostname SSRF in `web_url_read` |
| CVE-2026-54689 | 6.3 MEDIUM | mcp-searxng hardened-mode SSRF bypasses permit internal URL access |
No comments yet