What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). Prompt-injection-steerable SSRF in a niche MCP server; narrow exposure (requires agent prompt injection).
Why it matters
Shows the recurring pattern of MCP tools lacking destination validation — an SSRF primitive reachable through the agent, relevant to the broader MCP security sweep.
Attack vector
URLs passed to zotero_add_by_url are fetched with no destination validation, so SSRF reaches internal services directly or via redirects (CWE-918).
Affected systems
zotero-mcp 0.10.0 through 0.14.1 (zotero_add_by_url / _fetch_embedded_metadata)
Mitigation
Upgrade past 0.14.1; validate and block private/loopback/link-local destinations before fetching. See VulnCheck advisory.