Impact
The server component dbt-mcp exposes an unauthenticated GET /dbt_platform_context endpoint on 127.0.0.1:6785 after a user completes the dbt Platform OAuth flow. That endpoint returns a DbtPlatformContext object that contains the access_token and refresh_token persisted by the OAuth process. An attacker who can reach the localhost address or trick a victim’s browser via DNS rebinding can retrieve those credentials, gaining immediate read/write API access to the victim’s dbt Platform account, including projects, jobs, environment secrets, and other account data. Because the helper does not perform host validation and lacks TrustedHostMiddleware, arbitrary Host headers are accepted, enabling remote attackers to target the local endpoint from co‑located services.
Affected Systems
The issue is present in all releases of dbt‑labs dbt‑mcp before version 1.20.0. Users running any prior release are impacted.
Risk and Exploitability
CVSS score of 6.8 indicates medium severity. The EPSS score is < 1%, suggesting a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local to the host or remote via DNS rebinding, because the unauthenticated endpoint listens on the loopback interface and accepts arbitrary Host headers. If an attacker can reach the local address directly or can influence a victim’s browser to send requests to 127.0.0.1:6785, they can retrieve the tokens without authentication. With the stolen access and refresh tokens, they can act as the victim for immediate API calls and retain ongoing access through the refresh token, providing full read and write access to projects, jobs, environment secrets, and other account data.
OpenCVE Enrichment
Github GHSA