← Späť na vyhľadávanie CVE

CVE-2026-65056

mcp-webresearch

Popis

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the server-s Playwright browser to internal endpoints such as cloud instance metadata services, causing the server to return sensitive internal page content including credentials into the model context.

CVSS 8.2EPSS 0.231%Riziko 0.84
Zobraziť zdroj
Zverejnené
2026-07-21 21:16:54
Dotknuté verzie
==0.1.7
Typ
Webová aplikácia
Posledná úprava
2026-07-23 15:24:59
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N