Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: mcp-searxng

Found 5 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-94044
5.5 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
03-lovepreetSingh MCP route.ts create_file path traversal

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

MCP
  • ==f95d035c5317fad81af9828286631053ccb23546

Matching in nixpkgs

pkgs.mcpp

Matsui's C preprocessor

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ha-mcp

MCP server for controlling Home Assistant via natural language

  • nixos-unstable -
    • nixos-unstable-small 8.4.3
  • nixos-26.05 -
    • nixos-26.05-small 7.4.1

pkgs.numcpp

Templatized Header Only C++ Implementation of the Python NumPy Library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fff-mcp

MCP server for the fff file search engine

  • nixos-unstable -

pkgs.pdf-mcp

MCP server that lets AI agents work through large PDFs without overflowing their context

  • nixos-unstable -

pkgs.libXdmcp

X Display Manager Control Protocol library

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.libxdmcp

X Display Manager Control Protocol library

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.mcp-reva

Headless MCP server exposing Ghidra to AI agents

  • nixos-unstable -
    • nixos-unstable-small 7.3.0

pkgs.mcporter

TypeScript runtime and CLI for connecting to configured Model Context Protocol servers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mymcplus

PlayStation 2 memory card manager

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

pkgs.azure-mcp

Model Context Protocol server for Azure services

pkgs.mcp-nixos

MCP server for NixOS

  • nixos-unstable -
    • nixos-unstable-small 3.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.4.3

pkgs.mcp-proxy

MCP server which proxies other MCP servers from stdio to SSE or from SSE to stdio

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-k8s-go

MCP server connecting to Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.6.0

pkgs.forgejo-mcp

Model Context Protocol (MCP) server for interacting with the Forgejo REST API

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-gateway

Universal MCP Gateway - Single-port multiplexing with Meta-MCP for ~95% context token savings

  • nixos-unstable -
    • nixos-unstable-small 3.5.1
  • nixos-26.05 -

pkgs.mcp-grafana

MCP server for Grafana

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.3.0

pkgs.buttplug-mcp

Buttplug.io Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 0.0.1
  • nixos-26.05 -
    • nixos-26.05-small 0.0.1

pkgs.context7-mcp

MCP Server for up-to-date code documentation for LLMs and AI code editors

  • nixos-unstable -
    • nixos-unstable-small 4.0.3
  • nixos-26.05 -
    • nixos-26.05-small 2.2.5

pkgs.lean-lsp-mcp

MCP server for the Lean theorem prover via the Lean LSP

  • nixos-unstable -
  • nixos-26.05 -

pkgs.firecrawl-mcp

A Model Context Protocol (MCP) server that brings Firecrawl to MCP-compatible AI agents

  • nixos-unstable -

pkgs.norgolith-mcp

MCP (Model Context Protocol) server for Norgolith documentation

  • nixos-unstable -
    • nixos-unstable-small 1.2.0

pkgs.aks-mcp-server

Model Context Protocol server for Azure Kubernetes Service

  • nixos-unstable -
  • nixos-26.05 -

pkgs.markitdown-mcp

MCP server for the markitdown library

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.5

pkgs.mcp-server-git

Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-server-time

Model Context Protocol server providing tools for time queries and timezone conversions for LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.thunderbird-mcp

MCP server for Thunderbird - enables AI assistants to access email, contacts, and calendars

  • nixos-unstable -
    • nixos-unstable-small 0.7.4
  • nixos-26.05 -
    • nixos-26.05-small 0.5.0

pkgs.gitea-mcp-server

Gitea Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 1.6.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0

pkgs.clojure-mcp-light

Simple Clojure tooling for AI coding assistants

  • nixos-unstable -
    • nixos-unstable-small 0.2.2

pkgs.mcp-server-memory

MCP server for enabling memory for Claude through a knowledge graph

  • nixos-unstable -
  • nixos-26.05 -

pkgs.codebase-memory-mcp

High-performance C11 MCP server that indexes codebases into a persistent knowledge graph

  • nixos-unstable -

pkgs.fluxcd-operator-mcp

Kubernetes controller for managing the lifecycle of Flux CD

  • nixos-unstable -
  • nixos-26.05 -

pkgs.haskellPackages.mcp

A Servant-based Model Context Protocol (MCP) server for Haskell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-language-server

Model Context Protocol server to interact with language servers

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

pkgs.thunderbird-cli-mcp

MCP server that gives full access to your email through Mozilla Thunderbird

  • nixos-unstable -
    • nixos-unstable-small 1.0.2
  • nixos-26.05 -
    • nixos-26.05-small 1.0.2

pkgs.firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools automation

  • nixos-unstable -
    • nixos-unstable-small 0.9.9

pkgs.terraform-mcp-server

Terraform Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.5.2

pkgs.python313Packages.mcp

Official Python SDK for Model Context Protocol servers and clients

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.mcp

Official Python SDK for Model Context Protocol servers and clients

  • nixos-unstable -
  • nixos-26.05 -

pkgs.haskellPackages.mcp-types

Core types and protocol definitions for the Model Context Protocol (MCP)

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

pkgs.python313Packages.fastapi-mcp

Expose your FastAPI endpoints as Model Context Protocol (MCP) tools, with Auth

  • nixos-unstable -
    • nixos-unstable-small 0.4.0
  • nixos-26.05 -
    • nixos-26.05-small 0.4.0

pkgs.python314Packages.fastapi-mcp

Expose your FastAPI endpoints as Model Context Protocol (MCP) tools, with Auth

  • nixos-unstable -
    • nixos-unstable-small 0.4.0
  • nixos-26.05 -
    • nixos-26.05-small 0.4.0

Package maintainers

Dismissed
Permalink CVE-2026-58485
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 days, 12 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
mcp-searxng: DNS-resolved Private Hostname SSRF in `web_url_read`

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through src/index.ts and validates only the literal hostname in assertUrlAllowed() within src/url-reader.ts before undiciFetch() performs operating-system DNS resolution. A public-looking attacker-controlled hostname that resolves to a private, loopback, link-local, or cloud-metadata address therefore passes the lexical check and causes the MCP server to connect to the internal destination. In the default HTTP configuration, an unauthenticated network client can use this path to read internal services, expose credentials or service tokens, and enumerate reachable internal hosts; in STDIO deployments, prompt-influenced tool selection can provide the malicious URL. Direct private IP literals are blocked, and MCP_HTTP_ALLOW_PRIVATE_URLS remains an explicit opt-out. This issue is fixed in version 1.7.1.

Affected products

mcp-searxng
  • ==< 1.7.1

Matching in nixpkgs

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.2.0

Package maintainers

Introduced in nixpkgs at a non vulnerable version
Dismissed
Permalink CVE-2026-54689
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 days, 12 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
mcp-searxng hardened-mode SSRF bypasses permit internal URL access

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is enabled and MCP_HTTP_ALLOW_PRIVATE_URLS is not enabled because redirect targets are not revalidated, 0.0.0.0 is not classified as an internal address, and IPv4-mapped IPv6 literals canonicalized to hexadecimal form are not recognized. These inputs allow an attacker-influenced tool call to make the MCP server fetch loopback or internal HTTP resources and return content from local services, private APIs, service-mesh endpoints, or cloud metadata endpoints. The separate hostname-to-private-address case addressed by the earlier partial fix is not part of these residual bypasses. This issue is fixed in version 1.2.0.

Affected products

mcp-searxng
  • ==< 1.2.0

Matching in nixpkgs

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.2.0

Package maintainers

Not impacted, introduced in nixpkgs at a non vulnerable version
Dismissed
Permalink CVE-2026-58483
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 days, 12 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
mcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-reader.ts, where checkContentLength() treats a missing Content-Length header as an inconclusive preflight and the normal and error paths then consume the complete body with response.text(). A server that omits Content-Length can therefore bypass URL_READ_MAX_CONTENT_LENGTH_BYTES and force unbounded memory use. The resulting string is also processed by NodeHtmlMarkdown.translate(), increasing CPU consumption and allowing an unauthenticated HTTP client to cause denial of service. This issue is fixed in version 1.7.1.

Affected products

mcp-searxng
  • ==< 1.7.1

Matching in nixpkgs

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.2.0

Package maintainers

Got introduced in nixpkgs at a non vulnerable version
Untriaged
Permalink CVE-2026-54688
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 days, 20 hours ago Activity log
  • Created suggestion
mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllowed() in src/url-reader.ts runs only when MCP_HTTP_HARDEN is enabled, even though MCP_HTTP_HARDEN is disabled by default in src/http-security.ts. In the default configuration, an attacker who influences the URL selected by a user or AI agent can make the server fetch loopback, private-network, or cloud metadata endpoint resources and return their contents into the model context. file:// URLs remain rejected, and the separate DNS-resolution and redirect-validation bypasses are outside this record. This issue is fixed in version 1.2.0.

Affected products

mcp-searxng
  • ==< 1.2.0

Matching in nixpkgs

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.3.0

Package maintainers