Improper URL Validation Vulnerability in mcp-searxng by ihor-sokoliuk
CVE-2026-58485
7.1HIGH
What is CVE-2026-58485?
The mcp-searxng Model Context Protocol server has a vulnerability that allows an unauthenticated attacker to exploit improperly validated URLs. Through a flaw in the URL-reading functionality, attackers can manipulate the server to connect to private, loopback, or cloud-metadata addresses, potentially exposing sensitive internal services and credentials. This issue was addressed in version 1.7.1, which now enforces stricter validation to prevent unauthorized access.
Affected Version(s)
mcp-searxng < 1.7.1
