Junglewise Threat Intelligence

CVE-2026-42260: Aas-ee Open-WebSearch SSRF via IPv6 literal bypass in fetchWebContent

CVE-2026-42260 · Severity: high · CVSS 8.2 · Published 2026-05-12

Vendors: npm.

Executive brief

Open-WebSearch is a tool used by AI agents to search the web and retrieve website content. A security flaw allows attackers to bypass safety filters and force the tool to access internal network resources or private local services that should be unreachable. This could lead to the exposure of sensitive internal data, as the tool returns the full content of the retrieved internal pages to the requester.

Technical details

A non-blind Server-Side Request Forgery (SSRF) vulnerability exists in Open-WebSearch's `fetchWebContent` tool. The validation logic in `src/utils/urlSafety.ts` fails to recognize bracketed IPv6 literals (e.g., `[::1]`), causing them to bypass private IP checks. Additionally, the system does not perform DNS resolution during validation, allowing attackers to use hostnames that resolve to internal IP addresses (like 127.0.0.1). Because the tool returns the full response body to the caller, an unauthenticated attacker can read data from internal services. This issue is fixed in version 2.1.7.

Affected products

  • Aas-ee open-websearch <= 2.1.6

Timeline

  • 2026-04-26: advisory: GitHub Security Advisory published
  • 2026-05-12: disclosed: CVE-2026-42260 published
  • 2026-05-12: patched: Fixed in version 2.1.7

References