PT-2026-65888 · Rubygems · Mcp
CVE-2026-63118
·
Published
2026-07-29
·
Updated
2026-07-30
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mcp versions prior to 0.23.0
Description
The
MCP::Server::Transports::StreamableHTTPTransport component in the mcp gem fails to validate the HTTP Host or Origin request headers. This allows a malicious browser page to utilize DNS rebinding—a technique used to bypass the Same-Origin Policy—to access a locally running MCP server and invoke its exposed tools.Recommendations
Update to version 0.23.0.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp