THREAT OPS › Threat News › [GHSA] GHSA-hjwh-xvfw-qrwj (medium) — SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
[GHSA] GHSA-hjwh-xvfw-qrwj (medium) — SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
GHSA-hjwh-xvfw-qrwj Severity: medium CVE: None
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
### Summary
mcp-searxng version 1.11.0 exposes SearXNG Basic Authentication credentials embedded in the `SEARXNG_URL` environment variable.
When the server starts in STDIO mode and an MCP client connects, the complete `SEARXNG_URL`, including its usernam
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- http://MCP_POC_USER_7391:MCP_POC_PASS_7391@127.0.0.1:9url
- mcp_poc_pass_7391@example.invalidemail
Original source: https://github.com/advisories/GHSA-hjwh-xvfw-qrwj