CVE-2025-65512
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to internal network services.
Published:Dec 10, 2025
Last Modified:Jan 2, 2026
EPS:Dec 10, 2025
EPSS Score:0.00039
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Zcaceres
Product
Markdownify Mcp Server
Zcaceres
Markdownify Mcp Server
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
