Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77339— Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools

Quick assessment

Affected
F1bonacc1 process-compose
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Process Compose 是非容器化应用的调度器与编排器。在 1.120.0 版本之前,位于 中的 MCP SSE 监听器接受发往 端点及返回的消息端点来自浏览器的请求,但未对 Host 头进行校验,未验证 Origin 头,也未对调用方进行身份认证。 当启用了 MCP SSE 功能时,恶意网站可利用 DNS 重绑定技术访问回环地址上的监听器,并发出 MCP 请求。如果同时启用了 选项,攻击者便可以枚举进程状态、读取或搜索日志、截断日志,以及对本地进程执行启动、停止、重启或扩缩容操作;此外,配置的用户自定义工

CVSS 5.1 · Medium EPSS 0.21% · P12

Affected Version Matrix 1

VendorProduct Version RangeStatus
F1bonacc1 process-compose < 1.120.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77339

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Source: CVE Program / CVE List V5
Vulnerability Description
Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When MCP SSE is enabled, a malicious website can use DNS rebinding to reach the loopback listener and issue MCP requests. If expose_control_tools is enabled, the attacker can enumerate process state, read or search logs, truncate logs, and start, stop, restart, or scale local processes; configured user-defined tools can expose additional commands and output. The Gin REST API token middleware does not protect this separately started MCP listener. This issue is fixed in version 1.120.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F1bonacc1 process-compose < 1.120.0 -

II. Public POCs for CVE-2026-77339

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77339

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77339 (1)

Other References for CVE-2026-77339 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77339

No comments yet


Leave a comment