CVE-2026-55837: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in dbt-labs dbt-mcp
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context manager, to any process that can reach 127.0.0.1:6785. The absence of TrustedHostMiddleware allows a remote attacker to use DNS rebinding against a victim's browser because the helper accepts arbitrary Host headers, while a co-located process can request the endpoint directly. The stolen tokens provide immediate dbt Platform API access as the victim and persistent access through the refresh token, allowing access to or modification of projects, jobs, environment secrets, and related account data. This issue is fixed in version 1.20.0.
AI Analysis
Technical Summary
dbt-mcp versions before 1.20.0 contain a security flaw in the local OAuth helper where the GET /dbt_platform_context endpoint returns the full DbtPlatformContext, including sensitive access_token and refresh_token values, without requiring authentication or validating the Host header. This endpoint listens on 127.0.0.1:6785 and lacks TrustedHostMiddleware, allowing remote attackers to exploit DNS rebinding attacks against a victim's browser or local processes to retrieve tokens. The stolen tokens grant immediate and persistent access to the dbt Platform API as the victim, enabling unauthorized access or modification of projects, jobs, environment secrets, and related account data. The vulnerability is addressed in dbt-mcp version 1.20.0.
Potential Impact
Exposure of OAuth access and refresh tokens to unauthorized actors can lead to immediate and persistent unauthorized access to the dbt Platform API. Attackers can access or modify projects, jobs, environment secrets, and account data, potentially compromising the integrity and confidentiality of the victim's dbt environment. The vulnerability requires local network or DNS rebinding attack vectors but does not require prior privileges or user interaction beyond OAuth flow completion.
Mitigation Recommendations
Upgrade dbt-mcp to version 1.20.0 or later, where this vulnerability is fixed. The vendor has provided an official fix that adds authentication and host validation to the affected endpoint. Until upgrading, restrict access to 127.0.0.1:6785 and monitor for suspicious local or DNS rebinding activity. Patch status is confirmed fixed in 1.20.0.
CVE-2026-55837: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in dbt-labs dbt-mcp
Description
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context manager, to any process that can reach 127.0.0.1:6785. The absence of TrustedHostMiddleware allows a remote attacker to use DNS rebinding against a victim's browser because the helper accepts arbitrary Host headers, while a co-located process can request the endpoint directly. The stolen tokens provide immediate dbt Platform API access as the victim and persistent access through the refresh token, allowing access to or modification of projects, jobs, environment secrets, and related account data. This issue is fixed in version 1.20.0.
CVSS v3.1
Score 6.8medium
Affected software
dbt-labs
dbt-mcp
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
dbt-mcp versions before 1.20.0 contain a security flaw in the local OAuth helper where the GET /dbt_platform_context endpoint returns the full DbtPlatformContext, including sensitive access_token and refresh_token values, without requiring authentication or validating the Host header. This endpoint listens on 127.0.0.1:6785 and lacks TrustedHostMiddleware, allowing remote attackers to exploit DNS rebinding attacks against a victim's browser or local processes to retrieve tokens. The stolen tokens grant immediate and persistent access to the dbt Platform API as the victim, enabling unauthorized access or modification of projects, jobs, environment secrets, and related account data. The vulnerability is addressed in dbt-mcp version 1.20.0.
Potential Impact
Exposure of OAuth access and refresh tokens to unauthorized actors can lead to immediate and persistent unauthorized access to the dbt Platform API. Attackers can access or modify projects, jobs, environment secrets, and account data, potentially compromising the integrity and confidentiality of the victim's dbt environment. The vulnerability requires local network or DNS rebinding attack vectors but does not require prior privileges or user interaction beyond OAuth flow completion.
Mitigation Recommendations
Upgrade dbt-mcp to version 1.20.0 or later, where this vulnerability is fixed. The vendor has provided an official fix that adds authentication and host validation to the affected endpoint. Until upgrading, restrict access to 127.0.0.1:6785 and monitor for suspicious local or DNS rebinding activity. Patch status is confirmed fixed in 1.20.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-17T16:29:38.865Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8289355bf5e2cf557f784
Added to database: 09/14/2026, 17:02:11 UTC
Last enriched: 09/14/2026, 17:16:56 UTC
Last updated: 09/15/2026, 03:17:55 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.