Descripción
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the server-s Playwright browser to internal endpoints such as cloud instance metadata services, causing the server to return sensitive internal page content including credentials into the model context.
CVSS 8.2EPSS 0.231%Riesgo 0.84
Ver fuente- Publicación
- 2026-07-21 21:16:54
- Versiones afectadas
- ==0.1.7
- Tipo
- Aplicación web
- Última modificación
- 2026-07-23 15:24:59
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N