MEDIUM 6.3 GitHub
CVE-2026-54689
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
## Summary
`mcp-searxng` has a hardened-mode URL-reading feature intended to prevent `web_url_read` from reaching private or internal network resources.
PR #79 appears to address one SSRF class: hostnames that resolve to private or internal addresses under hardened mode. I tested PR #79 locally and confirmed that it blocks the DNS-resolves-to-loopback case.
However, several other hardened-mode SSRF bypasses still appear to remain:
1. Redirects from an allowed first-hop URL to a loopback/inte
Affected Products
- npm/mcp-searxng < 1.2.1
References
- https://github.com/advisories/GHSA-wppf-h75h-6pm6
- https://github.com/ihor-sokoliuk/mcp-searxng/security/advisories/GHSA-wppf-h75h-6pm6
- https://github.com/ihor-sokoliuk/mcp-searxng/releases/tag/v1.2.1
- https://github.com/advisories/GHSA-wppf-h75h-6pm6
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-19 via GitHub. Affected: npm/mcp-searxng < 1.2.1.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.