PT-2026-98194 · Db Hub · Db Hub
CVE-2026-61742
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DBHub versions prior to 0.22.5
Description
DBHub exposes an unauthenticated HTTP MCP endpoint when started in HTTP transport mode. The server attempts to prevent browser-origin access by verifying that the
Origin hostname matches the Host hostname and then reflecting the validated Origin into the Access-Control-Allow-Origin header. However, this mechanism does not prevent DNS rebinding, a technique where an attacker-controlled hostname is re-resolved to a victim-accessible server.If an attacker-controlled hostname rebinds to a DBHub HTTP server, both the
Origin and Host headers can match the attacker's hostname, allowing the server to accept the request and dispatch MCP tool calls. Consequently, a malicious website can invoke DBHub MCP tools from a victim's browser without prompt injection or model involvement. Depending on the configured permissions and credentials, this can allow an attacker to read, enumerate, and potentially write database contents via the /mcp endpoint.Recommendations
Update to version 0.22.5.
As a temporary workaround, avoid using the HTTP transport mode (
--transport http) and use the default stdio transport instead.
Restrict the HTTP transport to bind only to 127.0.0.1 to minimize exposure.Exploit
Fix
Origin Validation Error
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db Hub