SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-54689

MEDIUM · CVSS 6.3 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The mcp-searxng Model Context Protocol server is vulnerable to a bypass in the web_url_read URL policy, allowing attackers to exploit misconfigured settings to access internal HTTP resources, including local services and private APIs. This could lead to unauthorized data exposure and potential compromise of sensitive information. Organizations using versions prior to 1.2.0 should prioritize updating to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54689
Severity
MEDIUM
CVSS
6.3
EPSS
0.13%

Original NVD Description

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enabled and MCP_HTTP_ALLOW_PRIVATE_URLS is not enabled because redirect targets are not revalidated, 0.0.0.0 is not classified as an internal address, and IPv4-mapped IPv6 literals canonicalized to hexadecimal form are not recognized. These inputs allow an attacker-influenced tool call to make the MCP server fetch loopback or internal HTTP resources and return content from local services, private APIs, service-mesh endpoints, or cloud metadata endpoints. The separate hostname-to-private-address case addressed by the earlier partial fix is not part of these residual bypasses. This issue is fixed in version 1.2.0.