Security Advisory

CVE-2026-42260

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-12 14:09:05
Last updated 2026-05-14 19:10:56
Assigner GitHub_M
CVSS score 8.2
State PUBLISHED

Description

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.