Impact
The vulnerability allows an attacker to perform DNS rebinding because tiger-gh-mcp-server starts the MCP HTTP transport without enabling the host allow-list provided by the underlying SDK. A malicious page loaded in a victim’s browser can point a DNS name it controls to the local GitHub MCP endpoint, and the server will accept and forward the request. This gives the attacker indirect access to the internal endpoint from the victim’s browser, potentially exposing sensitive data or internal services.
Affected Systems
Timescale tiger‑gh‑mcp‑server, all commits before the recent patch that enabled DNS‑rebinding protection. No specific version numbers are listed.
Risk and Exploitability
The CVSS score of 7.6 indicates a high impact, and while the EPSS score is not available, the lack of a KEV listing means the vulnerability may not yet be widely exploited. The attack requires the attacker to control a DNS name and host a malicious page, so the vector is via an authenticated or unauthenticated web page that the user visits. The vulnerability would enable internal endpoint access from the victim’s browser alone.
OpenCVE Enrichment