DNS Rebinding Vulnerability in Neo4j Cypher MCP Server
CVE-2025-10193
7.4HIGH
What is CVE-2025-10193?
The DNS rebinding vulnerability in Neo4j's Cypher MCP server enables attackers to bypass Same-Origin Policy safeguards, allowing unauthorized execution of commands on locally running Neo4j MCP instances. This exploitation occurs through a malicious website that entices users to visit for an extended period, facilitating the DNS rebinding attack. The resulting security risk could compromise the integrity and availability of Neo4j systems, necessitating prompt attention to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
neo4j-cypher MCP server 0.2.2 <= 0.3.1
References
CVSS V4
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Evan Harris
