PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108583 54yyyu CVE debrief

A server-side request forgery vulnerability exists in zotero-mcp versions 0.10.0 through 0.14.1. This vulnerability allows attackers to reach internal services due to the _fetch_embedded_metadata function fetching URLs without destination validation. Attackers can exploit this by injecting prompts into the zotero_add_by_url function, causing requests to loopback, private, or link-local hosts directly or via redirects. This results in the leakage of citation meta-tags and error details.

Vendor
54yyyu
Product
zotero-mcp
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for the zotero-mcp application and its infrastructure should be aware of this vulnerability and take steps to verify and mitigate it. This includes verifying the version of zotero-mcp in use, restricting access to the zotero_add_by_url function, and monitoring for suspicious activity.

Why it matters

The CVE-2026-108583 vulnerability in zotero-mcp allows attackers to reach internal services via server-side request forgery, potentially leading to further attacks and information disclosure. Defenders should verify and mitigate this vulnerability to prevent exploitation.

  • Defenders need to verify if zotero-mcp versions 0.10.0 through 0.14.1 are in use and apply patches or mitigations if necessary.
  • Attackers can exploit this vulnerability to reach internal services, potentially leading to further attacks.
  • The leakage of citation meta-tags and error details could provide valuable information to attackers.
  • Defenders should monitor for suspicious activity related to the zotero-mcp application to detect potential exploitation.

Technical summary

The zotero-mcp application is vulnerable to server-side request forgery attacks due to the _fetch_embedded_metadata function not validating destinations when fetching URLs. This allows attackers to inject prompts into the zotero_add_by_url function, causing requests to loopback, private, or link-local hosts directly or via redirects, resulting in the leakage of citation meta-tags and error details.

Defensive priority

Defenders should prioritize verifying the vulnerability in their systems and applying patches or mitigations to prevent exploitation.

Recommended defensive actions

  • Verify if zotero-mcp versions 0.10.0 through 0.14.1 are in use and apply patches or mitigations if necessary.
  • Restrict access to the zotero_add_by_url function to prevent prompt injection attacks.
  • Monitor for suspicious activity related to the zotero-mcp application.
  • Perform a thorough review of the system configuration and network exposure to identify potential vulnerabilities.
  • Implement additional logging and monitoring to detect potential exploitation attempts.
  • Conduct a thorough risk assessment to identify potential impacts on the organization.
  • Review and update incident response plans to include procedures for responding to potential exploitation of this vulnerability.

Evidence notes

The vulnerability was reported in zotero-mcp versions 0.10.0 through 0.14.1. The _fetch_embedded_metadata function does not validate destinations when fetching URLs, allowing for server-side request forgery attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108583 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108583

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108583 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108583

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.