Server-Side Request Forgery in Zotero-mcp by 54yyyu
CVE-2026-108583
2.3LOW
What is CVE-2026-108583?
The Zotero-mcp versions 0.10.0 through 0.14.1 are prone to a server-side request forgery (SSRF) vulnerability due to inadequate validation of URLs fetched by the _fetch_embedded_metadata function. This flaw allows attackers to manipulate the agent through prompt injection, leveraging the zotero_add_by_url tool to initiate requests to loopback, private, or link-local addresses. Consequently, sensitive citation meta-tags and error details may be unintentionally exposed, posing a significant security risk to internal services.
Affected Version(s)
zotero-mcp 0.10.0 <= 0.14.1
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
