Improper URL Validation Vulnerability in mcp-searxng by ihor-sokoliuk
CVE-2026-58485

7.1HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-58485?

The mcp-searxng Model Context Protocol server has a vulnerability that allows an unauthenticated attacker to exploit improperly validated URLs. Through a flaw in the URL-reading functionality, attackers can manipulate the server to connect to private, loopback, or cloud-metadata addresses, potentially exposing sensitive internal services and credentials. This issue was addressed in version 1.7.1, which now enforces stricter validation to prevent unauthorized access.

Affected Version(s)

mcp-searxng < 1.7.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.