Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-65512

Опубликовано: 10 дек. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network services.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zcaceres:markdownify_mcp_server:*:*:*:*:*:*:*:*
Версия до 0.0.2 (включая)

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
github
около 2 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network services.

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-918