Vulnerability  ·  2026-10-11

zotero-mcp SSRF via zotero_add_by_url lets prompt-injected agents hit internal/loopback hosts (CVSS 4.2)

VulnerabilityLow impactGlobalCVE-2026-108583
Verified via NVD REST API (published 2026-10-10, VulnCheck). Prompt-injection-steerable SSRF in a niche MCP server; narrow exposure (requires agent prompt injection).
Shows the recurring pattern of MCP tools lacking destination validation — an SSRF primitive reachable through the agent, relevant to the broader MCP security sweep.
URLs passed to zotero_add_by_url are fetched with no destination validation, so SSRF reaches internal services directly or via redirects (CWE-918).
zotero-mcp 0.10.0 through 0.14.1 (zotero_add_by_url / _fetch_embedded_metadata)
Upgrade past 0.14.1; validate and block private/loopback/link-local destinations before fetching. See VulnCheck advisory.
NVD CVE-2026-108583NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →