Back to skill

Security audit

SearXNG Metasearch

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using a self-hosted SearXNG search service, with setup choices users should tighten before exposing it beyond their own machine.

Install only if you are comfortable running a local Docker service. Before starting it, bind Docker to 127.0.0.1 unless you intentionally want LAN or internet access, replace the placeholder secret with a random value, restrict firewall access, and pin the SearXNG image to a trusted version or digest.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Public Service Exposure with a Predictable Server Secret

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-38
Vulnerability Type: Insecure network configuration and hardcoded placeholder secret
Risk Level: Medium

Vulnerable Code

yaml
services:
  searxng:
    image: searxng/searxng:latest
    container_name: searxng
    ports:
      - "8080:8080"
    volumes:
      - ./searxng:/etc/searxng:rw
    environment:
      - SEARXNG_BASE_URL=http://localhost:8080/
    restart: unless-stopped
yaml
server:
  secret_key: "change-me-to-random-string"
  bind_address: "0.0.0.0"
  port: 8080

Technical Analysis

The documented Docker configuration publishes container port 8080 on every host interface because no loopback address is specified. SearXNG is also explicitly configured to bind to 0.0.0.0. Consequently, a user who copies this configuration may expose the service to other systems on the local network or, where firewall and routing rules permit, the Internet.

The configuration additionally provides a known placeholder value for secret_key. If the user does not replace it, any security mechanism that depends on this secret's unpredictability may be weakened. The exact consequences depend on the installed SearXNG version and enabled features; the documentation alone does not establish that this secret directly grants authentication bypass.

Attack Path

  1. A user copies the documented configuration without changing its defaults.
  2. Docker publishes port 8080 on all host interfaces, and SearXNG listens on all container interfaces.
  3. An attacker discovers the reachable service through network scanning or knowledge of the host address.
  4. The attacker submits requests to the exposed search endpoint, consuming service and upstream search-engine resources.
  5. If any enabled feature relies on the configured server secret, the known placeholder may facilitate attacks against that feature.

Impact Assessment

...[truncated 403 chars]

Remediation
View remediation

Remediation Suggestions

  • Publish the service only on loopback by default:

    yaml
    ports:
      - "127.0.0.1:8080:8080"
    
  • Generate a cryptographically random secret rather than documenting a reusable value, for example:

    bash
    openssl rand -hex 32
    
  • Clearly require users to replace the placeholder before startup and prevent deployment when the default value remains.

  • For remote access, place SearXNG behind a properly configured reverse proxy with TLS, authentication, request throttling, and network access controls.

  • Restrict inbound port 8080 using host firewall or cloud security-group rules.

  • Document that 0.0.0.0 and unrestricted Docker port publishing are unsuitable defaults for an otherwise local deployment.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Mutable Container Image Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 24
Vulnerability Type: Unpinned third-party container dependency
Risk Level: Medium

Vulnerable Code

yaml
image: searxng/searxng:latest

Technical Analysis

The setup retrieves the SearXNG container through the mutable latest tag. A mutable tag does not identify a fixed, reviewed artifact: its target can change whenever the publisher updates it. Installations and later image pulls can therefore execute code different from the version originally reviewed with this skill.

This creates a supply-chain and reproducibility weakness. It does not establish that the current upstream image is malicious, but it leaves users exposed to an upstream compromise, an accidentally defective release, or an incompatible update without a corresponding change to the audited project.

Attack Path

  1. The upstream latest tag is updated, or the registry or publisher account is compromised.
  2. A user follows the installation instructions, manually pulls the image, or recreates the container after the tag changes.
  3. Docker downloads the new artifact under the unchanged latest reference.
  4. The unreviewed image executes with the network access, writable configuration volume, environment, and restart policy granted by the Compose file.
  5. A compromised image could alter files in the mounted ./searxng directory, misuse network access, or consume resources within the privileges available to the container.

Impact Assessment

The impact is bounded by the container's effective privileges, Docker isolation, mounted paths, and network access. The shown configuration grants write access to ./searxng and network connectivity but does not grant privileged mode, host namespaces, the Docker socket, or broad host filesystem mounts. Therefore, arbitrary behavior inside the container and modification of the mounted configuration are plausible under a compromised-ima ...[truncated 82 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace latest with a reviewed release version and an immutable digest:

    yaml
    image: searxng/searxng:REVIEWED_VERSION@sha256:VERIFIED_DIGEST
    
  • Verify the digest against the official SearXNG release or registry metadata.

  • Use automated dependency monitoring to identify security updates without silently changing the deployed artifact.

  • Test updated images in a staging environment before changing the pinned digest.

  • Document a controlled upgrade process, including image provenance verification, vulnerability scanning, rollback steps, and review of release notes.

  • Where supported, verify signed container-image provenance before deployment.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The sample settings.yml binds the SearXNG server to 0.0.0.0, which exposes the service on all network interfaces. In the context of a privacy-focused self-hosted search tool, this can unintentionally make the instance reachable by other hosts on the LAN or beyond if port forwarding/firewall rules allow it, increasing the risk of unauthorized use, information leakage, or abuse without any warning in the documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The sample settings set default_lang: "en", which imposes a specific language choice in natural-language configuration. The documentation does not present this as optional, offer alternatives, or justify an English-only default for a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.