THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q87f-qc2r-2gw4 (medium) — SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

[GHSA] GHSA-q87f-qc2r-2gw4 (medium) — SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

highgithub_advisoriesPublished 2026-08-19

GHSA-q87f-qc2r-2gw4 Severity: medium CVE: CVE-2026-54688

SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694

### Summary The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF guard (asser

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q87f-qc2r-2gw4