{"id":"CVE-2026-42260","summary":"Open-WebSearch: SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`","details":"Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.","aliases":["GHSA-v228-72c7-fx8j"],"modified":"2026-08-12T03:51:22.827092144Z","published":"2026-05-12T14:09:05.888Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42260.json"},"references":[{"type":"ADVISORY","url":"https://github.com/Aas-ee/open-webSearch/security/advisories/GHSA-v228-72c7-fx8j"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42260.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42260"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aas-ee/open-websearch","events":[{"introduced":"0"},{"fixed":"739aef2bf7f2c822236bcce0f404c43b57f42503"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.1.7"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.1.6","v2.1.5","v2.0.2","v2.0.1","v2.0.0","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.6","v1.1.5.1","v1.1.5","v1.1.4.2","v1.1.4.1","v1.1.4","v1.1.1","v1.1","v1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42260.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}