CVE-2026-65056: mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses t...
Added to the CISA Known Exploited Vulnerabilities catalog on 21 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.2.
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved I...
Required action: Review and patch if applicable to your AI infrastructure.