mcp-webresearch 0.1.7 SSRF vulnerability via LLM prompt injection
A server-side request forgery vulnerability in mcp-webresearch 0.1.7 allows attackers to use prompt injection to steer an LLM into accessing internal network services and cloud metadata endpoints through the visit_page tool, exposing sensitive credentials.
Disclosed 21 July 2026 · Record updated 13 September 2026
Impact
Attackers can access internal network services and cloud instance metadata through the LLM-controlled visit_page tool, potentially obtaining sensitive credentials and internal page content.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65056
