PT-2025-23142 · Unknown · Mcp-Markdownify-Server

Raul Onitza-Klugman

·

Published

2025-05-29

·

Updated

2025-09-08

·

CVE-2025-5276

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mcp-markdownify-server versions all
Description The issue concerns Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpage-to-markdown, bing-search-to-markdown, and youtube-to-markdown tools to issue requests and read the responses to attacker-controlled URLs, potentially leaking sensitive information.
Recommendations As a temporary workaround, consider disabling the Markdownify.get() function until a patch is available. Restrict access to the webpage-to-markdown, bing-search-to-markdown, and youtube-to-markdown tools to minimize the risk of exploitation. Avoid using the Markdownify.get() function in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-5276
GHSA-FRQ9-3HP2-XVXG

Affected Products

Mcp-Markdownify-Server