Description
Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When MCP SSE is enabled, a malicious website can use DNS rebinding to reach the loopback listener and issue MCP requests. If expose_control_tools is enabled, the attacker can enumerate process state, read or search logs, truncate logs, and start, stop, restart, or scale local processes; configured user-defined tools can expose additional commands and output. The Gin REST API token middleware does not protect this separately started MCP listener. This issue is fixed in version 1.120.0.
Published: 2026-09-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Unvalidated Host and Origin headers in the MCP SSE listener let a malicious website, via DNS rebinding, target the loopback interface and send requests that enumerate and control local processes. Because the listener lacks authentication and gin middleware protection, an attacker can read or truncate logs, start, stop, restart, or scale processes, and invoke any user‑defined tools exposed by the application. This capability effectively gives the attacker full remote control over the host running process‑compose.

Affected Systems

F1bonacc1's process‑compose releases before version 1.120.0 are vulnerable. Any installation that enables the MCP SSE listener and sets expose_control_tools to true is at risk.

Risk and Exploitability

The vulnerability receives a CVSS score of 5.1, indicating moderate severity. EPSS is not available, suggesting limited, but non‑zero likelihood of exploitation. The feature is not listed in the CISA KEV catalog. An attacker can achieve this only from a browser that the victim visits; the attack requires DNS rebinding to reach the localhost listener. If the host is reachable from the internet and the service is exposed, the exploit is trivially possible – otherwise it requires a victim to load malicious JavaScript from an attacker‑controlled site.

Generated by OpenCVE AI on September 19, 2026 at 12:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade process‑compose to version 1.120.0 or later.
  • If the MCP SSE listener is not needed, disable it or bind it only to localhost.
  • Turn off the expose_control_tools setting to stop remote enumeration and process control.
  • Ensure the Gin REST API token middleware is applied to all interfaces or place the MCP listener behind authentication or a firewall.

Generated by OpenCVE AI on September 19, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5gm3-9crp-6g3v Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared F1bonacc1
F1bonacc1 process-compose
Vendors & Products F1bonacc1
F1bonacc1 process-compose

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When MCP SSE is enabled, a malicious website can use DNS rebinding to reach the loopback listener and issue MCP requests. If expose_control_tools is enabled, the attacker can enumerate process state, read or search logs, truncate logs, and start, stop, restart, or scale local processes; configured user-defined tools can expose additional commands and output. The Gin REST API token middleware does not protect this separately started MCP listener. This issue is fixed in version 1.120.0.
Title Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Weaknesses CWE-306
CWE-346
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

F1bonacc1 Process-compose
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T16:49:46.487Z

Reserved: 2026-08-20T19:24:11.618Z

Link: CVE-2026-77339

cve-icon Vulnrichment

Updated: 2026-09-18T16:49:41.201Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:00.663

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-77339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:04:43Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-346

    Origin Validation Error