5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether mcp-searxng is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.1
CVE-2026-58485
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
HIGH 7.5
CVE-2026-58483
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
MEDIUM 5.5
GHSA-hjwh-xvfw-qrwj
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
MEDIUM 6.3
CVE-2026-54689
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
MEDIUM 6.5
CVE-2026-54688
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes