CVE-2025-65512: Zcaceres Markdownify Mcp Server

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network services.

Affected products

  • Zcaceres Markdownify Mcp Server: up to and including 0.0.2

Published 2025-12-10. Last modified 2026-06-17.