PT-2026-49089 · Unknown · Model Context Protocol

·

CVE-2026-11624

·

Published

2026-06-13

·

Updated

2026-09-04

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Model Context Protocol versions prior to 0.25.0
Description Servers fail to validate the "Origin" header on incoming connections, which may allow DNS rebinding attacks. DNS rebinding is a method of bypassing the Same-Origin Policy to interact with services on a private network from a remote browser.
Recommendations Update to version 0.25.0 or later and use the --allowed-hosts or --allowed-origins flags to specify permitted hosts and origins at server startup.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11624
GHSA-76G7-M3XW-X9GR
GO-2026-6288
OPENSUSE-SU-2026:21761-1

Affected Products

Model Context Protocol