CVE-2026-108583 | Zotero MCP up to 0.14.1 URL Fetching _fetch_embedded_metadata server-side request forgery
A vulnerability was found in Zotero MCP up to 0.14.1. It has been declared as critical. Affected by this vulnerability is the function _fetch_embedded_metadata of the component URL Fetching. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-108583. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More