Local OAuth Vulnerability in dbt-mcp Server by dbt Labs
CVE-2026-55837
6.8MEDIUM
What is CVE-2026-55837?
The dbt-mcp server, designed for interacting with dbt, presents a security risk prior to version 1.20.0. The local OAuth helper exposes a GET endpoint that lacks necessary authentication and Host validation, allowing unauthorized access to sensitive token data, such as access and refresh tokens. This flaw enables an attacker to leverage DNS rebinding attacks through their browser, gaining access to user sessions and significant privileges on the dbt Platform API. Affected users are encouraged to upgrade to version 1.20.0 to ensure their environments remain secure.
Affected Version(s)
dbt-mcp < 1.20.0
