All vulnerabilities

CVE-2026-NONE · GHSA-2qr4-ww3x-mq4g

gomodel: DNS rebinding bypasses the project's own claimed Origin-check defense, exposing the aggregated MCP tool surface

moderateCVSS 5.8CWE-350
Vendor
ENTERPILOT
Package
gomodel go
Affected
>= v0.1.52, <= v0.1.79
Fixed in
v0.1.80
Disclosed
2026-08-30
Credit
Avishai Gonen
dns-rebindingmcp