THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wppf-h75h-6pm6 (medium) — SearXNG MCP Server: Additional hardened-mode SSRF bypasses

[GHSA] GHSA-wppf-h75h-6pm6 (medium) — SearXNG MCP Server: Additional hardened-mode SSRF bypasses

highgithub_advisoriesPublished 2026-08-19

GHSA-wppf-h75h-6pm6 Severity: medium CVE: CVE-2026-54689

SearXNG MCP Server: Additional hardened-mode SSRF bypasses

## Summary

`mcp-searxng` has a hardened-mode URL-reading feature intended to prevent `web_url_read` from reaching private or internal network resources.

PR #79 appears to address one SSRF class: hostnames that resolve to private or internal addresses under hardened mode. I tested

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wppf-h75h-6pm6