mzxrai mcp-webresearch是mzxrai团队的一款网络调研协作模块。 mzxrai mcp-webresearch 0.1.7版本及之前版本存在服务端请求伪造漏洞,该漏洞源于visit_page工具仅验证URL协议而未过滤私有或保留IP范围,导致服务端请求伪造,攻击者可通过提示注入控制LLM的URL参数,引导服务器Playwright浏览器访问内部端点(如云实例元数据服务),造成返回敏感内部页面内容(包括凭据)进入模型环境中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mzxrai | mcp-webresearch | ≤ 0.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mzxrai | mcp-webresearch | 0 ~ 0.1.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet