Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-19337: Server-side request forgery in mcp-google-search

A server-side request forgery vulnerability was identified in adenot mcp-google-search up to version 0.3.1 in the read_webpage component. The vulnerability allows manipulation of the url argument and is restricted to local execution.

Disclosed 9 August 2026 · Record updated 13 September 2026

Impact

Server-side request forgery vulnerability in read_webpage component affecting local execution

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19337