All vulnerabilities

CVE-2026-81102

Dropbox Dash MCP Server: DNS rebinding via missing Host header validation

lowCVSS 2.3CWE-346
Vendor
Dropbox
Package
mcp-server-dash npm
Affected
< commit 84567b7
Fixed in
commit 84567b7
Disclosed
2026-08-27
Credit
Avishai Gonen
dns-rebindingmcphost-header

Bug bounty awarded. Reported through Intigriti.