Impact
Unvalidated Host and Origin headers in the MCP SSE listener let a malicious website, via DNS rebinding, target the loopback interface and send requests that enumerate and control local processes. Because the listener lacks authentication and gin middleware protection, an attacker can read or truncate logs, start, stop, restart, or scale processes, and invoke any user‑defined tools exposed by the application. This capability effectively gives the attacker full remote control over the host running process‑compose.
Affected Systems
F1bonacc1's process‑compose releases before version 1.120.0 are vulnerable. Any installation that enables the MCP SSE listener and sets expose_control_tools to true is at risk.
Risk and Exploitability
The vulnerability receives a CVSS score of 5.1, indicating moderate severity. EPSS is not available, suggesting limited, but non‑zero likelihood of exploitation. The feature is not listed in the CISA KEV catalog. An attacker can achieve this only from a browser that the victim visits; the attack requires DNS rebinding to reach the localhost listener. If the host is reachable from the internet and the service is exposed, the exploit is trivially possible – otherwise it requires a victim to load malicious JavaScript from an attacker‑controlled site.
OpenCVE Enrichment
Github GHSA