zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 10 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.
Title zotero-mcp 0.10.0 through 0.14.1 SSRF via zotero_add_by_url Tool
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T15:57:51.278Z

Reserved: 2026-10-10T15:51:35.878Z

Link: CVE-2026-108583

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T16:16:31.667

Modified: 2026-10-10T16:16:31.667

Link: CVE-2026-108583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T17:30:05Z

Weaknesses