Executive brief
A security vulnerability exists in the Google-Research-MCP tool, which is used to integrate Google Research capabilities into the Model Context Protocol (MCP). An attacker can exploit this flaw to force the server to make unauthorized requests to internal systems or external websites. This could lead to the exposure of sensitive internal data, such as cloud metadata or internal network configurations, potentially compromising the security of the hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `extractContent` function within `src/services/content-extractor.service.ts` of the Google-Research-MCP project. The application accepts user-controlled URL parameters through the Model Context Protocol (MCP) tool interface and passes them directly to `axios.get()` without sufficient validation. Because the implementation lacks a destination allowlist or checks for private/loopback IP ranges, a remote attacker can force the server to perform HTTP GET requests. This can be used to probe internal network resources, access cloud instance metadata services (e.g., AWS IMDS), or interact with other internal APIs. The vulnerability was identified in version 0.1.0 and specific commit revisions (1e062d7 and ca613b7).
Affected products
- mixelpixx Google-Research-MCP 0.1.0
Timeline
- 2026-03-17: disclosed: Vulnerability reported by independent researcher Winegee via GitHub issues.
- 2026-04-03: advisory: CVE-2026-5470 published.