Security Flaw in Process Compose Scheduler Affects Users
CVE-2026-77339
5.1MEDIUM
What is CVE-2026-77339?
The MCP SSE listener in Process Compose prior to version 1.120.0 is vulnerable due to improper validation of the Host and Origin headers, allowing potential attackers to exploit this flaw via DNS rebinding techniques. When MCP SSE is enabled, an attacker could exploit this vulnerability to send unauthorized requests from malicious web pages, potentially allowing them to gain access to sensitive operational information, manipulate process states, and access logs. Furthermore, the lack of adequate protection from the Gin REST API token middleware for this listener exacerbates the risks associated with this vulnerability, enabling a range of harmful actions.
Affected Version(s)
process-compose < 1.120.0
