CVE-2026-19337: adenot mcp-google-search read_webpage index.ts server-side request forgery
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component readwebpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
adenot mcp-google-search (read_webpage) src/index.tsto a version that resolves this vulnerability.Patch f071d491b685011ca04e8ab8d586fc65f86bcee1