Local OAuth Vulnerability in dbt-mcp Server by dbt Labs
CVE-2026-55837

6.8MEDIUM

Key Information:

Vendor

Dbt-labs

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-55837?

The dbt-mcp server, designed for interacting with dbt, presents a security risk prior to version 1.20.0. The local OAuth helper exposes a GET endpoint that lacks necessary authentication and Host validation, allowing unauthorized access to sensitive token data, such as access and refresh tokens. This flaw enables an attacker to leverage DNS rebinding attacks through their browser, gaining access to user sessions and significant privileges on the dbt Platform API. Affected users are encouraged to upgrade to version 1.20.0 to ensure their environments remain secure.

Affected Version(s)

dbt-mcp < 1.20.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.