Model Context Protocol Server Vulnerability in dbt-MCP by dbt Labs
CVE-2026-44970
3.1LOW
What is CVE-2026-44970?
A vulnerability in dbt-mcp allows the DefaultUsageTracker to serialize and transmit sensitive tool call parameters, including SQL queries and execution variables, without proper redaction. This issue arises from default telemetry settings that enabled data collection unless explicitly disabled. Users are encouraged to update to version 1.17.1 where this risk is mitigated by implementing necessary redaction of sensitive data.
Affected Version(s)
dbt-mcp < 1.17.1
