LOW
54yyyu
CVE published 2026-10-10
CVE-2026-108583
A server-side request forgery vulnerability exists in zotero-mcp versions 0.10.0 through 0.14.1. This vulnerability allows attackers to reach internal services due to the _fetch_embedded_metadata function fetching URLs without destination validation. Attackers can exploit this by injecting prompts into the zotero_add_by_url function, causing requests to loopback, private, or link-local hosts directly or v [truncated]