{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/mcp-webresearch-0.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-65056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-webresearch 0.1.7"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","cloud","data-exfiltration","cve-2026-65056","llm-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-65056, has been discovered in version 0.1.7 of the mcp-webresearch application. This flaw enables attackers to bypass URL protocol validation within the \u003ccode\u003evisit_page\u003c/code\u003e tool by exploiting a lack of filtering for private or reserved IP ranges. The core issue lies in the tool's inability to prevent connections to internal network services, including loopback, link-local, and cloud metadata addresses, once the URL argument is controlled. Through prompt injection, adversaries can manipulate the application's underlying Large Language Model (LLM) to direct the server's Playwright browser to sensitive internal endpoints. This malicious navigation allows the attacker to retrieve and exfiltrate internal page content, such as system configurations and credentials, by embedding this information directly into the LLM's context. The vulnerability poses a significant risk of unauthorized data access and potential lateral movement within a compromised environment, impacting any organization deploying \u003ccode\u003emcp-webresearch\u003c/code\u003e version 0.1.7.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a deployed instance of the \u003ccode\u003emcp-webresearch 0.1.7\u003c/code\u003e application.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a prompt injection payload designed to manipulate the Large Language Model's (LLM) URL argument.\u003c/li\u003e\n\u003cli\u003eThe prompt injection payload includes a Uniform Resource Locator (URL) pointing to an internal network address, such as \u003ccode\u003ehttp://169.254.169.254/latest/meta-data/\u003c/code\u003e for cloud metadata services, or a private IP range.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003evisit_page\u003c/code\u003e tool within \u003ccode\u003emcp-webresearch\u003c/code\u003e processes the crafted URL, performing only protocol validation and failing to filter out private or reserved IP ranges.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003evisit_page\u003c/code\u003e tool directs the server's embedded Playwright browser to access the attacker-specified internal endpoint.\u003c/li\u003e\n\u003cli\u003eThe Playwright browser accesses the internal service (e.g., cloud metadata API), retrieving sensitive content like instance credentials, authentication tokens, or other internal application data.\u003c/li\u003e\n\u003cli\u003eThe sensitive content obtained from the internal service is returned and embedded into the LLM's model context.\u003c/li\u003e\n\u003cli\u003eThe attacker then extracts the sensitive information (e.g., credentials) from the LLM's output, achieving data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability allows attackers to gain unauthorized access to sensitive internal network services and cloud metadata APIs, including services running on loopback and link-local addresses. Successful exploitation leads to the exfiltration of critical data, such as system configurations, authentication tokens, and credentials, directly into the attacker-controlled LLM context. While specific victim counts are not available, any organization utilizing \u003ccode\u003emcp-webresearch\u003c/code\u003e version 0.1.7 is at risk. The direct consequence of a successful attack is a significant data breach, potentially enabling further lateral movement and persistent access within the targeted infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65056 by updating mcp-webresearch to a version where this SSRF vulnerability is remediated immediately.\u003c/li\u003e\n\u003cli\u003eImplement network egress filtering on servers running \u003ccode\u003emcp-webresearch\u003c/code\u003e to block outbound connections to private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and cloud metadata IPs like 169.254.169.254) from the \u003ccode\u003emcp-webresearch\u003c/code\u003e service.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003emcp-webresearch\u003c/code\u003e application logs for any unusual URL requests to internal or reserved IP addresses within the \u003ccode\u003evisit_page\u003c/code\u003e functionality.\u003c/li\u003e\n\u003cli\u003eMonitor network connection logs for outbound connections originating from the \u003ccode\u003emcp-webresearch\u003c/code\u003e process to cloud instance metadata APIs or other internal network services.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T21:23:09Z","date_published":"2026-07-21T21:23:09Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mcp-webresearch-ssrf/","summary":"A server-side request forgery (SSRF) vulnerability in mcp-webresearch version 0.1.7 allows attackers to bypass URL protocol validation by supplying private IP addresses, enabling them to leverage prompt injection to steer an LLM-controlled URL, forcing the server's Playwright browser to access internal network services and cloud instance metadata, which leads to the exfiltration of sensitive internal content, including credentials, into the model's context.","title":"Server-Side Request Forgery in mcp-webresearch (CVE-2026-65056)","url":"https://feed.craftedsignal.io/briefs/2026-07-mcp-webresearch-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Mcp-Webresearch 0.1.7","version":"https://jsonfeed.org/version/1.1"}