THREAT OPS › Threat News › [GHSA] GHSA-q87f-qc2r-2gw4 (medium) — SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
[GHSA] GHSA-q87f-qc2r-2gw4 (medium) — SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
GHSA-q87f-qc2r-2gw4 Severity: medium CVE: CVE-2026-54688
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694
### Summary The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF guard (asser
Indicators of compromise
- CVE-2026-54688cve
- http://127.0.0.1:url
- http://169.254.169.254/url
- 169.254.0.0/16cidr
- 0.0.0.0/8cidr
Original source: https://github.com/advisories/GHSA-q87f-qc2r-2gw4