PT-2026-95497 · Unknown · Process-Compose
CVE-2026-77339
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Process Compose versions prior to 1.120.0
Description
Process Compose is a scheduler and orchestrator for non-containerized applications. The MCP SSE listener in
src/mcp/server.go accepts browser-origin requests to the /sse endpoint and the subsequent message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. This allows a malicious website to use DNS rebinding—a technique that tricks a browser into making requests to a local IP address while believing it is communicating with a remote domain—to reach the loopback listener and issue MCP requests.If the
expose control tools setting is enabled, an attacker can enumerate process state, read, search, or truncate logs, and start, stop, restart, or scale local processes. Additionally, configured user-defined tools may expose further commands and output. The Gin REST API token middleware does not protect this listener as it is started separately.Recommendations
Update Process Compose to version 1.120.0.
As a temporary mitigation, disable the
expose control tools feature to prevent unauthorized process control and log access.Exploit
Fix
Origin Validation Error
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Process-Compose