Server-side Request Forgery in MCP-WebResearch by Geo-Chen
CVE-2026-65056
8.3HIGH
What is CVE-2026-65056?
MCP-WebResearch version 0.1.7 is vulnerable to a server-side request forgery issue. This vulnerability allows attackers to exploit the visit_page tool by inputting loopback, link-local, or cloud metadata addresses. The tool inadequately validates the URL protocol, failing to filter private or reserved IP ranges. As a result, attackers can manipulate the LLM to access internal cloud instance metadata services. This could lead to the exposure of sensitive information, including credentials, within the server's context.
Affected Version(s)
mcp-webresearch 0 <= 0.1.7
