SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Default settings let attacker-controlled URLs reach internal services or cloud metadata and return the response.

9 HIGH · 2 MED · 2 INFO · THREAT ORANGE · 13 items · Generated in 245s
Default settings let attacker-controlled URLs reach internal services or cloud metadata and return the response.
A run could access another user's private assistant metadata due to an authorization gap in run creation.
A prompt-injected MCP client could read or write files outside the project, exposing secrets or altering local system data.
A malicious prompt or client can read or write files the MCP server user can access, exposing secrets or altering local data.
Hardened mode can still reach internal services, exposing local data and enabling pivoting into private networks.
Attackers can read local files the server can access, exposing secrets and data outside the intended project scope.
An attacker can redirect API calls and steal the server's Contentful PAT, leading to unauthorized CMS access.
An auth bypass in webhook delivery can let one user affect another user's threads or runs.
Leaked Basic Auth credentials in logs or error responses can let clients or log readers access the SearXNG service.
This is a broad recap, not a specific flaw, so it is mainly awareness signal unless you track the mentioned incidents directly.
AI-assisted exploitation of Siemens PLCs raises risk of disruptive attacks on critical infrastructure operations.
Funding news with no disclosed exploit, flaw, or abuse case; useful for market tracking, not immediate security action.
Agent sandbox escapes can turn AI tooling into an attack path and show weak isolation controls defenders need to fix.