PT-2026-82568 · Unknown · Pg-Aiguide
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pg-aiguide versions prior to 0.5.1
Description
The MCP HTTP transport was started without enabling the host allow-list provided by the underlying SDK. Specifically, the
httpServer.ts file called the httpServerFactory() helper without setting the DNS-rebinding-protection option. This allows the transport to accept requests regardless of the host name provided. Consequently, a malicious webpage could use DNS rebinding—a technique that bypasses the Same-Origin Policy by changing the IP address associated with a domain name—to point a controlled name to the server's address and interact with the locally reachable MCP server via the visitor's browser.Recommendations
Update to version 0.5.1.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pg-Aiguide