Skip to main content

CVE-2026-55837: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in dbt-labs dbt-mcp

0
Medium
VulnerabilityCVE-2026-55837cvecve-2026-55837cwe-200cwe-306cwe-346
Published: 09/14/2026 (09/14/2026, 16:55:58 UTC)
Source: CVE Database V5
Vendor/Project: dbt-labs
Product: dbt-mcp

Description

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context manager, to any process that can reach 127.0.0.1:6785. The absence of TrustedHostMiddleware allows a remote attacker to use DNS rebinding against a victim's browser because the helper accepts arbitrary Host headers, while a co-located process can request the endpoint directly. The stolen tokens provide immediate dbt Platform API access as the victim and persistent access through the refresh token, allowing access to or modification of projects, jobs, environment secrets, and related account data. This issue is fixed in version 1.20.0.

CVSS v3.1

Score 6.8medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected software

dbt-labs

dbt-mcp

Affected versions
<1.20.0
GitHub Actionsmore threats →ai
dbt-labs/dbt-mcp
pkg:github/dbt-labs/dbt-mcp
Affected versions
<1.20.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 17:16:56 UTC

Technical Analysis

dbt-mcp versions before 1.20.0 contain a security flaw in the local OAuth helper where the GET /dbt_platform_context endpoint returns the full DbtPlatformContext, including sensitive access_token and refresh_token values, without requiring authentication or validating the Host header. This endpoint listens on 127.0.0.1:6785 and lacks TrustedHostMiddleware, allowing remote attackers to exploit DNS rebinding attacks against a victim's browser or local processes to retrieve tokens. The stolen tokens grant immediate and persistent access to the dbt Platform API as the victim, enabling unauthorized access or modification of projects, jobs, environment secrets, and related account data. The vulnerability is addressed in dbt-mcp version 1.20.0.

Potential Impact

Exposure of OAuth access and refresh tokens to unauthorized actors can lead to immediate and persistent unauthorized access to the dbt Platform API. Attackers can access or modify projects, jobs, environment secrets, and account data, potentially compromising the integrity and confidentiality of the victim's dbt environment. The vulnerability requires local network or DNS rebinding attack vectors but does not require prior privileges or user interaction beyond OAuth flow completion.

Mitigation Recommendations

Upgrade dbt-mcp to version 1.20.0 or later, where this vulnerability is fixed. The vendor has provided an official fix that adds authentication and host validation to the affected endpoint. Until upgrading, restrict access to 127.0.0.1:6785 and monitor for suspicious local or DNS rebinding activity. Patch status is confirmed fixed in 1.20.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-17T16:29:38.865Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa8289355bf5e2cf557f784

Added to database: 09/14/2026, 17:02:11 UTC

Last enriched: 09/14/2026, 17:16:56 UTC

Last updated: 09/15/2026, 03:17:55 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses