Security Flaw in Process Compose Scheduler Affects Users
CVE-2026-77339

5.1MEDIUM

Key Information:

Vendor

F1bonacc1

Vendor
CVE Published:
18 September 2026

What is CVE-2026-77339?

The MCP SSE listener in Process Compose prior to version 1.120.0 is vulnerable due to improper validation of the Host and Origin headers, allowing potential attackers to exploit this flaw via DNS rebinding techniques. When MCP SSE is enabled, an attacker could exploit this vulnerability to send unauthorized requests from malicious web pages, potentially allowing them to gain access to sensitive operational information, manipulate process states, and access logs. Furthermore, the lack of adequate protection from the Gin REST API token middleware for this listener exacerbates the risks associated with this vulnerability, enabling a range of harmful actions.

Affected Version(s)

process-compose < 1.120.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.