HIGH
mzxrai
CVE published 2026-07-21
CVE-2026-65056
The mcp-webresearch package, version 0.1.7, is vulnerable to a server-side request forgery (SSRF) attack. This vulnerability allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool. The tool only validates the URL protocol without filtering private or reserved IP ranges. Attackers can exploit this by using prompt injection [truncated]