Server-side Request Forgery in MCP-WebResearch by Geo-Chen
CVE-2026-65056

8.3HIGH

Key Information:

Vendor

Mzxrai

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65056?

MCP-WebResearch version 0.1.7 is vulnerable to a server-side request forgery issue. This vulnerability allows attackers to exploit the visit_page tool by inputting loopback, link-local, or cloud metadata addresses. The tool inadequately validates the URL protocol, failing to filter private or reserved IP ranges. As a result, attackers can manipulate the LLM to access internal cloud instance metadata services. This could lead to the exposure of sensitive information, including credentials, within the server's context.

Affected Version(s)

mcp-webresearch 0 <= 0.1.7

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.