All vulnerabilities

CVE-2026-NONE · GHSA-pf89-39r3-75vq

deepseek-mcp-server: DNS rebinding bypasses Host-validation guard in the shipped Docker default, exposing the DeepSeek API key

highCWE-346
Vendor
arikusi
Package
deepseek-mcp-server npm
Affected
>= 1.8.0, < 2.3.0
Fixed in
2.3.0
Disclosed
2026-09-05
Credit
Avishai Gonen
dns-rebindingmcpdocker