CVE-2026-11624
published 2026-06-13CVE-2026-11624: The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding…
PriorityP346critical9.4CVSS 4.0
AVNACLATNPRNUIAVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.15%
4.9th percentile
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "*", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "*", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mcp_toolbox_for_databases | < 0.25.0 | 0.25.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google MCP Toolbox for Databases up to 0.24.x origin validation (Issue 3113 / EUVD-2026-36650)
vuldb·2026-06-13·CVSS 9.4
CVE-2026-11624 [CRITICAL] Google MCP Toolbox for Databases up to 0.24.x origin validation (Issue 3113 / EUVD-2026-36650)
A vulnerability was found in Google MCP Toolbox for Databases up to 0.24.x and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to origin validation error.
This vulnerability is tracked as CVE-2026-11624. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks.
ghsa_unreviewed·2026-06-13
CVE-2026-11624 [CRITICAL] CWE-346 The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks.
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default to "*", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to "*", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-13
Published