THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hjwh-xvfw-qrwj (medium) — SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

[GHSA] GHSA-hjwh-xvfw-qrwj (medium) — SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

highgithub_advisoriesPublished 2026-08-19

GHSA-hjwh-xvfw-qrwj Severity: medium CVE: None

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

### Summary

mcp-searxng version 1.11.0 exposes SearXNG Basic Authentication credentials embedded in the `SEARXNG_URL` environment variable.

When the server starts in STDIO mode and an MCP client connects, the complete `SEARXNG_URL`, including its usernam

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hjwh-xvfw-qrwj