PT-2026-65888 · Rubygems · Mcp

CVE-2026-63118

·

Published

2026-07-29

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mcp versions prior to 0.23.0
Description The MCP::Server::Transports::StreamableHTTPTransport component in the mcp gem fails to validate the HTTP Host or Origin request headers. This allows a malicious browser page to utilize DNS rebinding—a technique used to bypass the Same-Origin Policy—to access a locally running MCP server and invoke its exposed tools.
Recommendations Update to version 0.23.0.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63118
GHSA-RJR6-RCGV-9M7M

Affected Products

Mcp