CVE-2026-108583
Received Received - Intake

Server-Side Request Forgery in Zotero MCP

Vulnerability report for CVE-2026-108583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
54yyyu zotero-mcp 0.10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

zotero-mcp 0.10.0 through 0.14.1 has a server-side request forgery (SSRF) vulnerability in the zotero_add_by_url tool. The _fetch_embedded_metadata function fetches URLs without validating the destination, allowing attackers to send requests to internal, loopback, or private network addresses via prompt injection. This bypasses existing SSRF protections in other parts of the application.

Detection Guidance

Monitor outbound requests from zotero-mcp processes, especially to loopback, private, or link-local addresses. Check logs for zotero_add_by_url tool calls with unusual URLs. Use network monitoring tools like tcpdump or Wireshark to inspect traffic from the application.

Impact Analysis

An attacker could trick the application into making requests to internal services, leaking metadata or error details. While limited to citation data, this could expose sensitive internal information or be used to probe internal networks. The impact is low severity but could aid in further attacks.

Compliance Impact

This SSRF vulnerability could potentially expose internal services or sensitive metadata, which may lead to unauthorized access to personal or confidential data. For GDPR, this could impact data protection obligations if personal data is leaked. For HIPAA, it might risk exposing protected health information if internal healthcare services are accessed. However, the vulnerability's blind nature limits direct data exfiltration, reducing but not eliminating compliance risks.

Mitigation Strategies

Upgrade zotero-mcp to the latest version where SSRF guards are applied to _fetch_embedded_metadata. Implement network-level restrictions to block outbound connections to private or internal addresses from the application.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart