mcp-searxng
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mcp-searxngpage 1 of 1
- CVE-2026-54688MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.2.12026-08-19
mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllowed…
- CVE-2026-54689MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.2.12026-08-19
mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enab…
Check whether mcp-searxng is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mcp-searxng CVEs against the assets you own.
Start Free Scan →