HIGH7.4
GHSA-frq9-3hp2-xvxg
Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Details
All versions of the package mcp-markdownify-server are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpage-to-markdown, bing-search-to-markdown, and youtube-to-markdown tools to issue requests and read the responses to attacker-controlled URLs, potentially leaking sensitive information.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/mcp-markdownify-server
Introduced in:
0No fixed version published yet for mcp-markdownify-server (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-5276[ADVISORY]
- https://github.com/zcaceres/markdownify-mcp/commit/0284aa8f34d32c65e20d8cda2d429b7943c9af03[WEB]
- https://github.com/zcaceres/markdownify-mcp[PACKAGE]
- https://github.com/zcaceres/markdownify-mcp/blob/224cf89f0d58616d2a5522f60f184e8391d1c9e3/src/server.ts#L20C17-L20C29[WEB]
- https://security.snyk.io/vuln/SNYK-JS-MCPMARKDOWNIFYSERVER-10249387[WEB]