Sceawere
Vulnerability Detail
CVE-2026-108583UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF in zotero-mcp Metadata Fetching
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 2h ago
- Vendor
- 54yyyu
- Product
- zotero-mcp
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-10-10T16:16:31.667Z",
"pubdate": "2026-10-10T16:16:31.667Z",
"executiveSummary": "The zotero-mcp package, specifically versions 0.10.0 through 0.14.1, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This security flaw originates from the improper handling of URL validation within the _fetch_embedded_metadata function, which facilitates the retrieval of metadata from user-provided citations. The vulnerability permits an attacker to perform unauthorized requests against arbitrary destinations, including loopback addresses (127.0.0.1), private network resources, and link-local services. By leveraging prompt injection techniques to manipulate an LLM agent into executing the zotero_add_by_url function, an adversary can bypass standard security boundaries. The exploitation of this vulnerability enables the exfiltration of sensitive information, such as metadata tags and verbose application error responses, from internal or otherwise unreachable network segments. The risk is significant as it transforms the agent into a proxy for internal network scanning and data extraction, potentially exposing services that rely on implicit network trust or lack robust authentication.",
"technicalDetails": "The root cause of the vulnerability resides in the _fetch_embedded_metadata function within the zotero-mcp framework. This function is responsible for performing HTTP requests to remote resources to resolve and extract citation metadata. Crucially, the implementation fails to perform adequate destination validation or allow-list filtering on the target URL prior to the initiation of the network request. Consequently, the application does not distinguish between legitimate public-facing scholarly repositories and unauthorized internal infrastructure.\nThe attack flow utilizes a technique involving prompt injection. An attacker crafts a malicious input designed to influence the LLM agent that integrates with zotero-mcp. By successfully manipulating the agent's logic, the attacker induces the execution of the zotero_add_by_url function with a crafted, malicious URL as the argument. The vulnerable code path subsequently passes this input to _fetch_embedded_metadata without sanitization or network-level restrictions.\nBecause the underlying HTTP client is not restricted from accessing restricted address spaces, the library will attempt to resolve and connect to internal loopback, link-local, or private RFC 1918 network addresses. This behavior is further exacerbated if the library follows HTTP redirects without re-validating the destination after a 3xx response, allowing an attacker to bypass simple initial checks if they were present. The resulting interaction allows the agent to reach internal services that would otherwise be protected by a firewall or network boundary.\nThe exploitation impact involves the disclosure of internal application state. When the target service responds to the forged request, the zotero-mcp agent processes the response body to extract metadata. If the internal service responds with HTML or XML, the agent may inadvertently include internal meta-tags or verbose error trace information in the returned output. An attacker can use these artifacts to map internal network topology, identify running services, or capture data returned by internal APIs. No authentication is typically required for the initial prompt injection, and the impact is limited only by the outbound network connectivity of the host system executing the zotero-mcp process."
}