Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-42260: SSRF in Open-WebSearch MCP server URL safety checks

Open-WebSearch, a multi-engine MCP server, CLI and local daemon for agent web search and content retrieval, had URL safety checks (isPublicHttpUrl/assertPublicHttpUrl) that failed to recognise bracketed IPv6 literals and did not resolve DNS, allowing non-blind SSRF with response bodies returned to the caller. The issue is fixed in version 2.1.7.

Disclosed 12 May 2026 · Record updated 13 September 2026

Impact

Attackers could make the MCP server fetch internal or otherwise restricted resources and receive the response body (non-blind SSRF). Affected versions prior to 2.1.7.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42260