
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
searxng
Advanced tools
A network search server based on MCP technology, providing privacy-friendly web search functionality using the SearXNG search engine.
This server provides the following main features:
web_search - Perform web search using SearXNG
query (string): The search querycategories (array): Search categories, e.g. ['general', 'images', 'news']engines (array): Search engines, e.g. ['google', 'bing', 'duckduckgo']language (string): Language code for search, default is "en"max_results (integer): Maximum number of results, default is 10 (1-100)time_range (string): Time range filter ('day', 'week', 'month', 'year')If a search cannot be completed (the instance is unreachable, rate-limits the request, or returns a malformed response), the tool returns an error result describing the failure rather than an empty result list.
Each server process admits up to eight concurrent searches. Further calls return
an error immediately and can be retried later. --timeout bounds the complete
network operation, including streaming the response; cancellation closes the
active request. Responses are limited to 2 MiB before JSON parsing.
The configured instance must serve /search directly: redirects are rejected.
The client requests Accept-Encoding: identity and rejects compressed responses
to prevent unbounded decompression. Result fields are also truncated to their
existing limits. Missing or non-list results and upstream error objects are
reported as failures, while a valid empty list remains a successful search.
Application logs omit search queries and upstream exception text. The CLI keeps
HTTP dependency logging at WARNING even when --log-level=DEBUG is selected.
| Option | Default | Description |
|---|---|---|
--instance-url | https://searx.party | SearXNG instance to query. Must be an absolute http(s) URL. |
--timeout | 30 | Total search network timeout, in seconds. |
--log-level | WARNING | Logging verbosity: DEBUG, INFO, WARNING, ERROR, CRITICAL. Logs are written to stderr. |
--transport | stdio | Transport to serve on: stdio or http. |
--host | 127.0.0.1 | Host to bind when --transport=http. |
--port | 8000 | Port to bind when --transport=http. |
By default the server speaks stdio, which is what local MCP clients
(Claude Desktop, IDE integrations, uvx) launch it with.
For remote access, --transport http serves the Streamable HTTP
transport at /mcp:
searxng --transport http --host 127.0.0.1 --port 8000
# endpoint: http://127.0.0.1:8000/mcp
The legacy SSE transport is intentionally not implemented. It was superseded by Streamable HTTP in the 2025-03-26 MCP protocol revision and should not be used for new deployments.
Security: the server performs no authentication, so it binds to
127.0.0.1 by default. Only pass --host 0.0.0.0 on a trusted network,
or put an authenticating reverse proxy in front of it.
Binding to a non-loopback host also disables the MCP SDK's DNS-rebinding
protection, which it can only enable automatically for 127.0.0.1,
localhost, and ::1. On a loopback bind a forged Host header is
rejected with 421 Misdirected Request; on a public bind any Host is
accepted. The server logs a warning at startup when this applies.
To set up SearXNG as an MCP server, add one of the following to your MCP configuration file:
UVX setup:
"mcpServers": {
"searxng": {
"command": "uvx",
"args": ["searxng", "--instance-url=https://searx.party"]
}
}
This launches the server over stdio, which is the right choice for a local client.
Remote setup (Streamable HTTP):
Start the server as a long-running process:
searxng --transport http --host 0.0.0.0 --port 8000 \
--instance-url=https://searx.party
Then point the client at its /mcp endpoint:
"mcpServers": {
"searxng": {
"url": "http://your-host:8000/mcp"
}
}
Note the --host 0.0.0.0 needed to accept connections from other
machines, and the security caveat above: the server is unauthenticated,
so restrict it to a trusted network or front it with an authenticating
reverse proxy.
{
"name": "web_search",
"arguments": {
"query": "climate change research",
"categories": ["general"],
"engines": ["google"],
"language": "en",
"max_results": 15,
"time_range": "month"
}
}
You can use the MCP inspector to debug the server:
npx @modelcontextprotocol/inspector uvx searxng
AGPLv3+ License - see LICENSE for details.
FAQs
MCP server providing SearXNG-based web search functionality
We found that searxng demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.