PatchSiren cyber security CVE debrief
CVE-2026-108583 54yyyu CVE debrief
A server-side request forgery vulnerability exists in zotero-mcp versions 0.10.0 through 0.14.1. This vulnerability allows attackers to reach internal services due to the _fetch_embedded_metadata function fetching URLs without destination validation. Attackers can exploit this by injecting prompts into the zotero_add_by_url function, causing requests to loopback, private, or link-local hosts directly or via redirects. This results in the leakage of citation meta-tags and error details.
- Vendor
- 54yyyu
- Product
- zotero-mcp
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for the zotero-mcp application and its infrastructure should be aware of this vulnerability and take steps to verify and mitigate it. This includes verifying the version of zotero-mcp in use, restricting access to the zotero_add_by_url function, and monitoring for suspicious activity.
Why it matters
The CVE-2026-108583 vulnerability in zotero-mcp allows attackers to reach internal services via server-side request forgery, potentially leading to further attacks and information disclosure. Defenders should verify and mitigate this vulnerability to prevent exploitation.
- Defenders need to verify if zotero-mcp versions 0.10.0 through 0.14.1 are in use and apply patches or mitigations if necessary.
- Attackers can exploit this vulnerability to reach internal services, potentially leading to further attacks.
- The leakage of citation meta-tags and error details could provide valuable information to attackers.
- Defenders should monitor for suspicious activity related to the zotero-mcp application to detect potential exploitation.
Technical summary
The zotero-mcp application is vulnerable to server-side request forgery attacks due to the _fetch_embedded_metadata function not validating destinations when fetching URLs. This allows attackers to inject prompts into the zotero_add_by_url function, causing requests to loopback, private, or link-local hosts directly or via redirects, resulting in the leakage of citation meta-tags and error details.
Defensive priority
Defenders should prioritize verifying the vulnerability in their systems and applying patches or mitigations to prevent exploitation.
Recommended defensive actions
- Verify if zotero-mcp versions 0.10.0 through 0.14.1 are in use and apply patches or mitigations if necessary.
- Restrict access to the zotero_add_by_url function to prevent prompt injection attacks.
- Monitor for suspicious activity related to the zotero-mcp application.
- Perform a thorough review of the system configuration and network exposure to identify potential vulnerabilities.
- Implement additional logging and monitoring to detect potential exploitation attempts.
- Conduct a thorough risk assessment to identify potential impacts on the organization.
- Review and update incident response plans to include procedures for responding to potential exploitation of this vulnerability.
Evidence notes
The vulnerability was reported in zotero-mcp versions 0.10.0 through 0.14.1. The _fetch_embedded_metadata function does not validate destinations when fetching URLs, allowing for server-side request forgery attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108583 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108583
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108583 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108583
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/54yyyu/zotero-mcp/blob/v0.14.1/src/zotero_mcp/tools/write.py
-
Source reference
Unverified legacy reference
URL: https://github.com/54yyyu/zotero-mcp/issues/326
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/zotero-mcp-generic-url-metadata-ssrf
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/zotero-mcp-0.10.0-through-0.14.1-ssrf-via-zotero-add-by-url-tool
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.