mcp-searxng 是一个模型上下文协议(Model Context Protocol)服务器,通过 SearXNG 为 AI 助手提供网络搜索和 URL 读取功能。在 1.7.1 版本之前, 中的 函数会将调用者提供的 URL 传递给 中的 函数。在该函数中, 将缺失的 响应头视为一种不明确的预检情况,随后正常路径和错误路径都会通过 消费完整的响应体。因此,如果服务器省略了 头,就可以绕过 限制,从而强制产生无界的内存使用。此外,生成的字符串还会被 处理,进一步增加 CPU 消耗,使得未认证的 HTTP 客户
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ihor-sokoliuk | mcp-searxng | < 1.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ihor-sokoliuk | mcp-searxng | < 1.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58485 | 7.1 HIGH | mcp-searxng: DNS-resolved Private Hostname SSRF in `web_url_read` |
| CVE-2026-54688 | 6.5 MEDIUM | mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by default (MCP_ |
| CVE-2026-54689 | 6.3 MEDIUM | mcp-searxng hardened-mode SSRF bypasses permit internal URL access |
No comments yet