Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hjwh-xvfw-qrwj
  • npm/mcp-searxng
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses 19 Aug
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-wppf-h75h-6pm6
  • npm/mcp-searxng
SearXNG MCP Server: Additional hardened-mode SSRF bypasses 19 Aug
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-q87f-qc2r-2gw4
  • npm/mcp-searxng
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off) 19 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-mrvx-jmjw-vggc
  • npm/mcp-searxng
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read` 19 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-xcqx-9jf5-w339
  • npm/mcp-searxng
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` 19 Jun
  • Fix available
  • Severity - 7.5 (High)