Process Compose: browser DNS rebinding lets websites control local MCP tools
The process-compose MCP surface lacks Host header validation, so any website a developer visits can reach it via DNS rebinding and drive local process control tools.
ls -la ./cves
24 published disclosures, disclosed through GitHub Security Advisories. Every entry links to its advisory and fix; technical writeups are added as each disclosure clears. Filter by severity, year or ecosystem, or search the text.
The process-compose MCP surface lacks Host header validation, so any website a developer visits can reach it via DNS rebinding and drive local process control tools.
Unvalidated user-controlled URLs in the GitLab MCP server let an attacker make the host issue requests to arbitrary destinations, reaching internal services.
The Streamable HTTP transport accepts requests without validating the Host header, letting a malicious page reach the locally-bound MCP server via DNS rebinding.
The bundled @agent-infra MCP servers listen on all interfaces with no authentication, exposing arbitrary command execution to anyone who can reach the host.
The python_code_executor tool can be escaped, and the service is reachable without authentication - together yielding remote code execution.
With the Host header allow-list disabled, a malicious web page can reach the locally-bound tiger-slack MCP server through DNS rebinding.
With the Host header allow-list disabled, a malicious web page can reach the locally-bound tiger-gh-mcp-server through DNS rebinding.
The Streamable HTTP transport exposes its endpoints with no authentication, so anyone able to reach the port can invoke the server's tools.
The execute_ruby tool's PTY handling can be escaped, letting an attacker run arbitrary operating-system commands on the host.
The Host header allow-list is disabled by configuration in pg-aiguide, so a browser-based DNS rebinding attack can reach the local MCP server.
mcp-go's HTTP transports do not validate the Host header before 0.56.0, allowing a malicious web page to reach a locally-bound server through DNS rebinding.
The MCP server omits Host header validation, so a browser-based DNS rebinding attack can reach the locally-bound service.
The CLI sends stored credentials to whatever endpoint is configured, without validating it - so a crafted configuration exfiltrates the user's API token.
The GenieACS MCP Streamable HTTP transport does not validate the Host header, so a malicious web page can reach the locally-bound service through DNS rebinding.
The setup endpoint answers without authentication, so anyone who can reach the host can redirect the AI backend's traffic.
Combining missing Host header validation with unauthenticated management routes, a malicious web page can rebind to the local MCP server and seize control of the Jupyter backend.
In standalone HTTP mode the management routes require no authentication, allowing an attacker to reconfigure and take over the Jupyter backend the MCP server controls.
dbx-web fails open when no password is configured: authentication is skipped entirely, so an unauthenticated client can execute arbitrary SQL against connected databases.
The Tapo MCP server validates no Host header, so a web page the user visits can reach the local server and drive smart-home controls.
With no Host header validation, any site the user visits can reach the local MCP server and read, write or delete Todoist data.
The DBHub HTTP transport omits Host header validation, so a browser-based DNS rebinding attack can issue unauthenticated SQL queries from outside the local network.
The local AnkiMCP HTTP tools require no authentication and do not validate the Host header, exposing them to DNS rebinding.
The MCP HTTP transport listens on all interfaces with no authentication, while the documentation describes it as localhost-only.
The yutu MCP HTTP transport requires no authentication, so anyone who can reach the port can act on the operator's YouTube account: deleting videos, playlists and comments.
No CVEs match that filter.