Description
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context manager, to any process that can reach 127.0.0.1:6785. The absence of TrustedHostMiddleware allows a remote attacker to use DNS rebinding against a victim's browser because the helper accepts arbitrary Host headers, while a co-located process can request the endpoint directly. The stolen tokens provide immediate dbt Platform API access as the victim and persistent access through the refresh token, allowing access to or modification of projects, jobs, environment secrets, and related account data. This issue is fixed in version 1.20.0.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass via Token Leakage
Action: Apply patch
AI Analysis

Impact

The server component dbt-mcp exposes an unauthenticated GET /dbt_platform_context endpoint on 127.0.0.1:6785 after a user completes the dbt Platform OAuth flow. That endpoint returns a DbtPlatformContext object that contains the access_token and refresh_token persisted by the OAuth process. An attacker who can reach the localhost address or trick a victim’s browser via DNS rebinding can retrieve those credentials, gaining immediate read/write API access to the victim’s dbt Platform account, including projects, jobs, environment secrets, and other account data. Because the helper does not perform host validation and lacks TrustedHostMiddleware, arbitrary Host headers are accepted, enabling remote attackers to target the local endpoint from co‑located services.

Affected Systems

The issue is present in all releases of dbt‑labs dbt‑mcp before version 1.20.0. Users running any prior release are impacted.

Risk and Exploitability

CVSS score of 6.8 indicates medium severity. The EPSS score is < 1%, suggesting a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local to the host or remote via DNS rebinding, because the unauthenticated endpoint listens on the loopback interface and accepts arbitrary Host headers. If an attacker can reach the local address directly or can influence a victim’s browser to send requests to 127.0.0.1:6785, they can retrieve the tokens without authentication. With the stolen access and refresh tokens, they can act as the victim for immediate API calls and retain ongoing access through the refresh token, providing full read and write access to projects, jobs, environment secrets, and other account data.

Generated by OpenCVE AI on September 20, 2026 at 23:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade dbt‑mcp to version 1.20.0 or later to remove the unauthenticated endpoint
  • Restrict inbound access to port 6785 so that only trusted services or hosts can reach the local endpoint
  • Add host validation or enable TrustedHostMiddleware in the FastAPI application to reject requests with arbitrary Host headers

Generated by OpenCVE AI on September 20, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jr33-mw75-7j8f dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Dbt-labs
Dbt-labs dbt-mcp
Vendors & Products Dbt-labs
Dbt-labs dbt-mcp

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the full DbtPlatformContext, including access_token and refresh_token values persisted by the context manager, to any process that can reach 127.0.0.1:6785. The absence of TrustedHostMiddleware allows a remote attacker to use DNS rebinding against a victim's browser because the helper accepts arbitrary Host headers, while a co-located process can request the endpoint directly. The stolen tokens provide immediate dbt Platform API access as the victim and persistent access through the refresh token, allowing access to or modification of projects, jobs, environment secrets, and related account data. This issue is fixed in version 1.20.0.
Title dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
Weaknesses CWE-200
CWE-306
CWE-346
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Dbt-labs Dbt-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:20:19.376Z

Reserved: 2026-06-17T16:29:38.865Z

Link: CVE-2026-55837

cve-icon Vulnrichment

Updated: 2026-09-16T15:20:11.280Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:48.547

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-346

    Origin Validation Error