PT-2026-82568 · Unknown · Pg-Aiguide

·

CVE-2026-81095

·

Published

2026-08-27

·

Updated

2026-08-30

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pg-aiguide versions prior to 0.5.1
Description The MCP HTTP transport was started without enabling the host allow-list provided by the underlying SDK. Specifically, the httpServer.ts file called the httpServerFactory() helper without setting the DNS-rebinding-protection option. This allows the transport to accept requests regardless of the host name provided. Consequently, a malicious webpage could use DNS rebinding—a technique that bypasses the Same-Origin Policy by changing the IP address associated with a domain name—to point a controlled name to the server's address and interact with the locally reachable MCP server via the visitor's browser.
Recommendations Update to version 0.5.1.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81095

Affected Products

Pg-Aiguide