{"id":"CVE-2026-108583","title":"zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation","summary":"zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the …","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-918"],"published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T16:16:31.667","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108583","references":[{"url":"https://github.com/54yyyu/zotero-mcp/blob/v0.14.1/src/zotero_mcp/tools/write.py#L2035-L2089","label":"disclosure@vulncheck.com"},{"url":"https://github.com/54yyyu/zotero-mcp/issues/326","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/@haind/zotero-mcp-generic-url-metadata-ssrf","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zotero-mcp-0.10.0-through-0.14.1-ssrf-via-zotero-add-by-url-tool","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T16:27:15.749Z","slug":"CVE-2026-108583","body":"## Overview\n\nzotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}